PEN-200 Port Redirection and Tunneling Practice Question
You have compromised a Linux host that sits on both your external network and an isolated internal network containing a Windows server with SMB exposed. From your Kali machine you need to interact with the SMB service as if it were local. Which single command creates the correct tunnel?
⚠ Common exam trap
Test-takers frequently confuse the direction of -L and -R, assuming a remote forward will somehow expose an internal service to your local machine.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ssh -L 127.0.0.1:445:10.10.10.20:445 user@10.10.10.10
A local port forward created with -L makes your attacking machine listen on a chosen local address and port, then relays that traffic through the SSH server to a destination reachable from the pivot. Binding to 127.0.0.1 keeps the forwarded port private to your host, which is appropriate when only your local tools need to reach the internal SMB service. Remote and dynamic forwards solve different problems and do not give a direct local-to-internal mapping here.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ssh -D 445 user@10.10.10.10
Why it's wrong here
The -D flag creates a dynamic SOCKS proxy on the specified local port, here 445, which is not a SOCKS-friendly port and does not target the internal SMB server. A SOCKS proxy is also not a direct point-to-point tunnel to 10.10.10.20:445, so SMB tooling that expects a raw TCP connection to an SMB port will not work through it without additional proxying.
- ✗
ssh -R 127.0.0.1:445:10.10.10.20:445 user@10.10.10.10
Why it's wrong here
A remote forward (-R) asks the SSH server to listen on its own loopback and forward back to your client. That would make the pivot listen on 127.0.0.1:445 and send traffic to your machine, which does not help you reach the internal SMB server from your Kali box. The direction of the tunnel is reversed from what this scenario requires.
- ✓
ssh -L 127.0.0.1:445:10.10.10.20:445 user@10.10.10.10
Why this is correct
This local forward binds port 445 on your own loopback and tunnels traffic through the pivot at 10.10.10.10 to the internal SMB host 10.10.10.20 on port 445. Because the pivot can reach both networks, your SMB client can now connect to 127.0.0.1:445 and reach the internal server without exposing the port on your external interface.
- ✗
ssh -L 0.0.0.0:445:10.10.10.20:445 user@10.10.10.10
Why it's wrong here
This binds port 445 on all interfaces of your Kali machine, exposing the tunnel to anyone who can reach your host. While it technically forwards traffic to the internal SMB server, it is unnecessarily permissive and creates a security and detection risk. The scenario only requires local access, so loopback binding is the correct and safer choice.
About these practice questions
One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.