PEN-200 Port Redirection and Tunneling Practice Question
When using SSH tunneling, what is the primary security risk of using the '-R' flag in a multi-user environment?
⚠ Common exam trap
Students frequently focus only on the functionality of the tunnel, missing the multi-user environment context where bound ports on shared servers expose sensitive entry points to unauthorized local users.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It exposes the tunnel to all users on the remote server.
The -R flag binds a port on the remote (attacker/server) machine. If that machine has other users logged in, they can potentially connect to the forwarded port and gain access to the internal network through the tunnel you established. This exposes your pivot to unintended access by other users on the same machine, which is a significant risk in shared lab or production environments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
It exposes the tunnel to all users on the remote server.
Why this is correct
By default, ports forwarded with -R bind to the loopback interface on the remote server. However, if the server configuration allows it or if you bind to all interfaces, any user on that server can access the forwarded port, effectively hijacking your pivot for their own network activities or malicious use.
- ✗
It forces the remote server to enable password-less login.
Why it's wrong here
SSH remote port forwarding is a network-level feature and has no dependency on or control over the server's authentication settings. It does not alter the server's password policies or enable password-less login. These are separate configuration aspects managed within the sshd_config file on the remote server host.
- ✗
It requires the remote server to have a GUI installed.
Why it's wrong here
SSH port forwarding is a command-line-based protocol feature that operates independently of the host's operating system environment. It does not require a graphical user interface on the server. The protocol functions perfectly on headless systems, which are the standard for jump hosts and internal infrastructure servers.
- ✗
It automatically disables logs on the jump host.
Why it's wrong here
SSH does not disable logs when a tunnel is created. Logging remains controlled by the server's audit and logging configuration (e.g., syslog, auth.log). The creation of a tunnel might be logged, but the feature itself does not modify or suppress existing server logging behaviors for security or maintenance purposes.
About these practice questions
Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.