PEN-200 Port Redirection and Tunneling Practice Question
While pivoting through a compromised host, you want to route an Impacket tool through a SOCKS proxy you established with SSH dynamic forwarding. The tool does not support SOCKS natively. Which approach allows the Impacket tool to use the proxy correctly?
⚠ Common exam trap
The trap here is assuming any proxy environment variable will redirect a raw-socket tool through a SOCKS listener created by SSH dynamic forwarding.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run the Impacket tool under proxychains, ensuring the proxychains configuration lists the SOCKS proxy and uses the appropriate proxy type.
Proxychains is the standard bridge for tools that cannot speak SOCKS. It hooks the process's network calls and forwards them to the SOCKS listener created by SSH dynamic forwarding, allowing Impacket tools to reach internal services. The configuration file must correctly identify the proxy address, port, and SOCKS version, otherwise connections fail or leak outside the tunnel.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add a static route on the attacking machine for the internal subnet pointing at the SSH server's IP address.
Why it's wrong here
A static route directs packets to an IP next hop, but the pivot is not a router and will not forward arbitrary IP traffic. The SSH tunnel only carries traffic that is deliberately proxied into it, so adding a route results in packets being dropped or sent to a host that cannot route them.
- ✗
Set the HTTP_PROXY environment variable to point at the SSH dynamic forwarding port before launching the Impacket tool.
Why it's wrong here
HTTP_PROXY only affects applications that honor it for HTTP requests. An SSH dynamic forward exposes a SOCKS proxy, not an HTTP proxy, and Impacket's SMB-oriented tools do not consume HTTP_PROXY for their raw socket connections, so this variable would be ignored for the traffic in question.
- ✓
Run the Impacket tool under proxychains, ensuring the proxychains configuration lists the SOCKS proxy and uses the appropriate proxy type.
Why this is correct
Proxychains intercepts the tool's socket calls and redirects them through the configured SOCKS proxy, which bridges the tool to the internal network. Because Impacket lacks native SOCKS support, wrapping it in proxychains is the standard method. The configuration must specify the correct proxy type and port for the SSH dynamic forward to work.
- ✗
Re-run the SSH session with the -L flag instead of -D so Impacket can connect directly to the internal host through a fixed local port.
Why it's wrong here
Switching to a single local forward would only expose one specific host and port, not a general route for arbitrary destinations. Impacket tools frequently contact multiple services, so a single -L tunnel cannot cover the needed traffic and would force one tunnel per target service.
About these practice questions
This PEN-200 question is part of Courseiva's 285-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.