Courseiva

PEN-200 · topic practice

Port Redirection and Tunneling practice questions

Port redirection and tunneling on PEN-200 covers pivoting through compromised hosts to reach isolated internal services. You must build SSH local/remote/dynamic forwards, use Chisel and socat, and route tools like nmap and CrackMapExec through proxies. Questions present a pivot scenario and ask which syntax, bind behavior, or tool mode reaches the target service correctly.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Port Redirection and Tunneling

What the exam tests

What to know about Port Redirection and Tunneling

Be able to choose and write the correct SSH -L, -R, or -D command, Chisel client/server invocation, or socat relay for a given pivot, and know which interface a forward binds to. Getting the direction and bind address right is the single most important thing.

SSH local forwarding (-L) syntax to reach a service bound to localhost on a pivot host

SSH remote forwarding (-R) and how GatewayPorts controls binding to all interfaces

Chisel client/server reverse tunneling over HTTP to bypass outbound firewall restrictions

Using proxychains with SSH -D SOCKS proxy to run nmap, SMB, and other tools through a pivot

Watch out for

Common Port Redirection and Tunneling exam traps

  • ▸Confusing -L and -R direction: -L pulls a remote port to your machine, -R pushes your port to the remote host
  • ▸Assuming SSH -R binds all interfaces by default; GatewayPorts no restricts it to loopback on the server
  • ▸Forgetting proxychains only proxies TCP connect, so nmap needs -sT and no ICMP or UDP scans

Practice set

Port Redirection and Tunneling questions

20 questions · select your answer, then reveal the explanation

You are performing a penetration test and have gained shell access to a Windows machine. You need to forward traffic to an internal database server at 10.0.0.5:3306. Which TWO of the following tools allow you to perform this task natively or via uploaded binaries on Windows?

Refer to the exhibit. You have executed Chisel on a compromised Windows host to establish a connection to your attacking machine. Based on the output, what is the current state of your proxy capability?

Exhibit

C:\Windows\Temp> chisel.exe client 10.10.14.5:8000 R:socks
2023/10/01 10:00:00 connecting to http://10.10.14.5:8000
2023/10/01 10:00:01 proxy#0: dynamic proxy enabled

You need to pivot through a compromised host to reach an internal database. You are using SSH remote port forwarding. If you execute 'ssh -R 9000:localhost:3306 user@attacker-ip', which direction does the traffic flow for this tunnel?

When setting up a pivot using SSH tunneling, which THREE factors are critical to ensure the tunnel remains stable and functional for long-term access?

When using SSH for port redirection, what is the significance of binding to the loopback address (127.0.0.1) versus the 'all interfaces' (0.0.0.0) address?

When setting up a SOCKS proxy via SSH, which TWO configurations on your local attacking machine are required for the proxy to work correctly with browser-based tools?

What is the primary function of the 'proxychains' tool when used in conjunction with a SOCKS proxy?

You have compromised a Linux jump host and need to access an internal-only web application running on 192.168.1.50:8080. The jump host has SSH access to your Kali machine, but inbound connections are blocked. Which command allows you to access this internal service from your local browser?

Refer to the exhibit. You have successfully executed the SSH command, but when you browse to http://localhost:8080, the connection is refused. What is the most likely reason for this failure?

Exhibit

ssh -v -L 8080:10.10.10.5:80 victim@10.10.10.10
debug1: Connecting to 10.10.10.10 [10.10.10.10] port 22.
debug1: Connection established.
... 
debug1: Local connections to LOCALHOST:8080 forwarded to remote address 10.10.10.5:80
debug1: Local forwarding listening on 127.0.0.1 port 8080.

You are performing a pivoting operation and need to use Chisel. Which TWO of the following statements regarding Chisel's operation are correct?

Question 11easymultiple choice
Review the full routing breakdown →

You are configuring proxychains on your Kali Linux attacking machine to route Nmap scans through a SOCKS proxy established via SSH. Which configuration file parameter must you modify or verify to ensure TCP connect scans operate correctly through the proxy?

Question 12mediummultiple choice
Review the full routing breakdown →

You have obtained a foothold on a dual-homed Linux host at 10.10.10.5, which can reach an internal MySQL server at 172.16.5.20:3306. Your attacking machine cannot route to 172.16.5.20. You want a simple, tool-free way to make the MySQL service reachable through the pivot without installing anything on the compromised host. Which command best accomplishes this?

During a Windows penetration test, you gain access to a dual-homed host with interfaces on 10.10.10.0/24 and 172.16.1.0/24. The internal network 172.16.1.0/24 is only reachable through this host. You want to forward traffic from your attacking machine (192.168.0.50) to an internal web server at 172.16.1.100:80. You have administrative access to the Windows host and can upload tools. Which of the following commands, executed on the compromised Windows host, will create the necessary port forward?

You have compromised a Linux host that acts as a pivot into a segmented network. You want to use SSH remote port forwarding to expose an internal service (192.168.1.100:3389) to your attacking machine. You run the command: ssh -R 9001:192.168.1.100:3389 user@attacker.com. Which TWO statements about this setup are correct? (Choose two.)

During an internal engagement you compromised a Windows host that has outbound HTTPS access to your team server but no inbound access from the internet. You plan to use ligolo-ng to pivot into the internal network. Which TWO statements about deploying ligolo-ng in this situation are correct? (Choose two.)

You have an SSH session to a compromised Linux host and need to reach an internal service on 10.20.30.40:8080 from a second internal host that you also control. You want the second host to connect through the first host's tunnel without installing additional software on either internal machine. Which SSH remote forward correctly publishes the service so the second host can reach it?

You have compromised a Linux host that dual-homes between your attacking network (192.168.1.0/24) and an internal network (10.0.0.0/24). The internal network contains a server at 10.0.0.5 running an SSH service on port 22. You want to use SSH dynamic port forwarding to create a SOCKS proxy on your attacking machine, allowing you to scan the internal network with Nmap. Which command should you run on your attacking machine?

You are using Chisel to create a reverse tunnel from a compromised Windows host to your attacking Linux machine. The compromised host cannot initiate outbound connections on arbitrary ports, but it can reach your machine on port 443. You have downloaded the Chisel binary to both machines. Which TWO of the following commands will correctly establish the tunnel? (Choose two.)

You have compromised a Linux host that can reach an internal network. You want to use SSH remote port forwarding to expose an internal service to your attacking machine. Which command, executed on the compromised host, will forward the internal service at 10.0.0.10:3306 to port 3306 on your attacking machine (192.168.1.50)?

Question 20hardmultiple choice
Review the full subnetting walkthrough →

You have established a SOCKS proxy on your attacking machine using SSH dynamic port forwarding through a compromised Linux host. You now need to run an Nmap SYN scan against an internal subnet. Which of the following commands will correctly route the Nmap scan through the proxy?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Port Redirection and Tunneling sessions

Start a Port Redirection and Tunneling only practice session

Every question in these sessions is drawn from the Port Redirection and Tunneling domain — nothing else.

Related practice questions

Related PEN-200 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the PEN-200 exam test about Port Redirection and Tunneling?
Be able to choose and write the correct SSH -L, -R, or -D command, Chisel client/server invocation, or socat relay for a given pivot, and know which interface a forward binds to. Getting the direction and bind address right is the single most important thing.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Port Redirection and Tunneling questions in a focused session?
Yes — the session launcher on this page draws every question from the Port Redirection and Tunneling domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other PEN-200 topics?
Use the topic links above to move to related areas, or go back to the PEN-200 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the PEN-200 exam covers. They are not copied from any real exam or dump site.