PEN-200 Port Redirection and Tunneling Practice Question
You have a Windows host with outbound internet access but want to avoid installing a full agent. You decide to use Chisel to pivot. Which statement accurately describes how Chisel establishes the tunnel in this scenario?
⚠ Common exam trap
The trap here is reversing the client and server roles and assuming the tool requires a routed interface like a TUN device.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Chisel client on the compromised host connects outbound to the Chisel server on your attacking machine, and the server can expose a SOCKS proxy on your side.
Chisel's client dials the server, so a compromised host with only outbound access can still establish a tunnel. When the server is started with reverse tunneling and SOCKS support, the operator gets a SOCKS proxy locally that routes through the client into the internal network. This makes Chisel a practical choice when a full agent is undesirable.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Chisel encrypts traffic only when the --tls flag is used, and otherwise sends plaintext over the wire.
Why it's wrong here
Chisel secures the transport by default using TLS with a generated certificate, and the --tls flag controls whether the server requires a client certificate, not whether encryption is applied. Claiming plaintext by default mischaracterizes the tool's transport security and could lead to incorrect assumptions during an engagement.
- ✗
The Chisel server must run on the compromised host so the client on your attacking machine can pull traffic from the internal network.
Why it's wrong here
Running the server on the victim would require inbound connectivity to the compromised host, which the scenario says is unavailable. The client-server roles in Chisel are fixed by design: the client initiates the connection, so placing the server on the victim inverts the intended deployment and breaks the egress-only assumption.
- ✓
The Chisel client on the compromised host connects outbound to the Chisel server on your attacking machine, and the server can expose a SOCKS proxy on your side.
Why this is correct
Chisel uses a client-server model where the client dials the server. Running the server with reverse tunneling and SOCKS options lets the server-side listener present a SOCKS proxy on your attacking machine, while the client on the victim maintains the outbound connection. This fits hosts that cannot accept inbound connections.
- ✗
Chisel requires a kernel TUN interface on both endpoints to carry the tunneled traffic.
Why it's wrong here
Chisel operates at the application layer over HTTP or TLS and does not create TUN interfaces. It exposes SOCKS or fixed port forwards rather than a routed interface, so tools must be SOCKS-aware or wrapped with proxychains. Requiring TUN on both sides describes a different class of tunneling tool.
About these practice questions
One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.