Courseiva

PEN-200 Port Redirection and Tunneling Practice Question

During an internal penetration test, you compromise a Linux machine that acts as a pivot host, but the target internal web server only permits HTTP traffic from localhost. Which local port forwarding syntax allows you to securely access this web application via your attacking machine?

⚠ Common exam trap

Candidates frequently confuse local port forwarding with remote port forwarding, incorrectly choosing the reverse direction when trying to access internal targets from the attacker workstation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ssh -L 8080:10.0.4.5:80 user@pivot-host

Local port forwarding binds a port on your attacking machine and forwards any connections through the compromised pivot host to the destination service. This technique bypasses strict perimeter controls by tunneling traffic securely across an existing SSH session, enabling interaction with internal services restricted strictly to localhost interfaces.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ssh -R 8080:10.0.4.5:80 user@pivot-host

    Why it's wrong here

    This command configures remote port forwarding rather than local port forwarding. Remote port forwarding opens a listening port on the remote pivot host instead of binding a port locally on your attacking machine for your browser to access.

  • ✗

    ssh -D 1080 user@pivot-host

    Why it's wrong here

    This command establishes a dynamic SOCKS proxy rather than local port forwarding. While a SOCKS proxy successfully routes traffic through the pivot host, it requires proxychains configuration rather than directly mapping a static local port to a specific destination.

  • ✓

    ssh -L 8080:10.0.4.5:80 user@pivot-host

    Why this is correct

    This command correctly establishes local port forwarding by binding port 8080 on your attacking machine and forwarding traffic through the pivot host to the internal web server at 10.0.4.5 on port 80, satisfying the localhost restriction requirement.

  • ✗

    ssh -w 0:0 user@pivot-host

    Why it's wrong here

    This command attempts to configure a Layer 2 TUN/TAP interface tunnel over SSH. While powerful for full network routing, it is overly complex for accessing a single web application and requires administrative privileges on both ends.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.