Courseiva

PEN-200 Port Redirection and Tunneling Practice Question

When performing SSH dynamic port forwarding with the -D flag, what is the primary benefit compared to local port forwarding (-L)?

⚠ Common exam trap

Candidates often confuse dynamic port forwarding with local port forwarding, assuming they need to create a new tunnel every time they want to access a different internal service.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It enables routing to multiple internal hosts dynamically.

Dynamic port forwarding creates a SOCKS proxy, which allows the user to route traffic to any destination reachable by the remote jump host. Unlike local port forwarding, which requires specifying a target IP and port upfront, dynamic forwarding is flexible. This is essential during the discovery phase of a penetration test, as it allows tools like Nmap or browser-based tools to explore an entire internal network segment without individual tunnel configurations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It provides a faster connection speed than local forwarding.

    Why it's wrong here

    Dynamic port forwarding does not inherently offer higher throughput than local port forwarding. Both methods utilize the same underlying SSH encryption and transport mechanisms. Performance differences are usually related to network latency or the overhead of proxying, not the method of forwarding itself, as both are equally efficient.

  • ✓

    It enables routing to multiple internal hosts dynamically.

    Why this is correct

    Dynamic port forwarding acts as a SOCKS proxy, allowing client applications to route traffic through the SSH server to any destination reachable by that server. This eliminates the need to create individual -L tunnels for every specific internal IP or service, providing much greater flexibility during network enumeration.

  • ✗

    It is more secure because it disables encryption.

    Why it's wrong here

    SSH port forwarding, including dynamic forwarding, always maintains the encrypted tunnel provided by the SSH protocol. There is no option to disable encryption while using these flags. The security of the tunnel is a core feature of using SSH for pivoting, and it cannot be intentionally downgraded to plaintext.

  • ✗

    It allows the user to run commands on the remote machine.

    Why it's wrong here

    Dynamic port forwarding is exclusively for network traffic proxying. It does not provide remote command execution capabilities. For executing commands on the jump host, a standard SSH shell session is required, which is a separate function from the port forwarding features provided by the -D or -L flags.

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.