Courseiva

PEN-200 Port Redirection and Tunneling Practice Question

During an internal penetration test, you compromise a Linux host that has outbound SSH access to your attacking machine but cannot directly reach an internal Windows server on 10.10.10.5:445. You need to forward SMB traffic through the compromised host so that your local tools can connect to 10.10.10.5:445. Which command should you run from your attacking machine to create the required tunnel?

⚠ Common exam trap

Many exam-takers confuse local and remote port forwarding directions, leading to a tunnel that listens on the pivot host instead of on the attacking machine.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ssh -L 127.0.0.1:4450:10.10.10.5:445 user@compromised-host

A local port forward with -L listens on your attacking machine and forwards through the SSH server to a destination reachable from that server. The syntax is -L [bind_address:]local_port:target_host:target_port. Here, the compromised host can reach 10.10.10.5:445, so binding locally and pointing the forward at the internal SMB service provides the required access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ssh -R 127.0.0.1:4450:10.10.10.5:445 user@compromised-host

    Why it's wrong here

    Remote port forwarding (-R) would make the compromised host listen on its own loopback port 4450 and forward connections back to your attacking machine's 10.10.10.5:445. That direction is opposite to what you need; your local tools would not be able to reach the internal server through this tunnel because the listening socket resides on the pivot host, not locally.

  • ✗

    ssh -D 127.0.0.1:4450 user@compromised-host

    Why it's wrong here

    The -D option creates a dynamic SOCKS proxy on local port 4450, not a direct static forward to 10.10.10.5:445. While you could later use a SOCKS-capable tool to reach the internal server, the scenario asks for a direct tunnel for SMB tools; using -D alone does not automatically forward SMB traffic and requires additional client configuration.

  • ✗

    ssh -L 10.10.10.5:445:127.0.0.1:4450 user@compromised-host

    Why it's wrong here

    This command attempts to bind a local listener on 10.10.10.5, an address that does not exist on your attacking machine, and forwards it to your own loopback port 4450. It reverses the source and destination and uses an invalid local bind address, so it fails to create the intended tunnel to the internal SMB service.

  • ✓

    ssh -L 127.0.0.1:4450:10.10.10.5:445 user@compromised-host

    Why this is correct

    This command creates a local port forward from your attacking machine's loopback interface on port 4450 to 10.10.10.5:445 through the compromised host. Because the compromised host can reach the internal Windows server, the SSH server relays the connection. You would then point your SMB client to 127.0.0.1:4450 to access the internal service.

About these practice questions

One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.