Courseiva

PEN-200 Port Redirection and Tunneling Practice Question

You have compromised a Linux host that sits on both your external network and an isolated internal network containing a Windows server with SMB exposed. From your Kali machine you need to interact with the SMB service as if it were local. Which single command creates the correct tunnel?

⚠ Common exam trap

Test-takers frequently confuse the direction of -L and -R, assuming a remote forward will somehow expose an internal service to your local machine.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ssh -L 127.0.0.1:445:10.10.10.20:445 user@10.10.10.10

A local port forward created with -L makes your attacking machine listen on a chosen local address and port, then relays that traffic through the SSH server to a destination reachable from the pivot. Binding to 127.0.0.1 keeps the forwarded port private to your host, which is appropriate when only your local tools need to reach the internal SMB service. Remote and dynamic forwards solve different problems and do not give a direct local-to-internal mapping here.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ssh -D 445 user@10.10.10.10

    Why it's wrong here

    The -D flag creates a dynamic SOCKS proxy on the specified local port, here 445, which is not a SOCKS-friendly port and does not target the internal SMB server. A SOCKS proxy is also not a direct point-to-point tunnel to 10.10.10.20:445, so SMB tooling that expects a raw TCP connection to an SMB port will not work through it without additional proxying.

  • ✗

    ssh -R 127.0.0.1:445:10.10.10.20:445 user@10.10.10.10

    Why it's wrong here

    A remote forward (-R) asks the SSH server to listen on its own loopback and forward back to your client. That would make the pivot listen on 127.0.0.1:445 and send traffic to your machine, which does not help you reach the internal SMB server from your Kali box. The direction of the tunnel is reversed from what this scenario requires.

  • ✓

    ssh -L 127.0.0.1:445:10.10.10.20:445 user@10.10.10.10

    Why this is correct

    This local forward binds port 445 on your own loopback and tunnels traffic through the pivot at 10.10.10.10 to the internal SMB host 10.10.10.20 on port 445. Because the pivot can reach both networks, your SMB client can now connect to 127.0.0.1:445 and reach the internal server without exposing the port on your external interface.

  • ✗

    ssh -L 0.0.0.0:445:10.10.10.20:445 user@10.10.10.10

    Why it's wrong here

    This binds port 445 on all interfaces of your Kali machine, exposing the tunnel to anyone who can reach your host. While it technically forwards traffic to the internal SMB server, it is unnecessarily permissive and creates a security and detection risk. The scenario only requires local access, so loopback binding is the correct and safer choice.

About these practice questions

One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.