PEN-200 Port Redirection and Tunneling Practice Question
You have compromised a Linux jump host and need to access an internal web application on 192.168.1.50:80 that is firewalled from your local machine. You have SSH access to the jump host. Which command should you execute on your local machine to securely access the application via your browser?
⚠ Common exam trap
Candidates often mix up the local and remote port numbers in the -L command syntax, leading to connection failures because the local port is not bound to the intended target service.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ssh -L 8080:192.168.1.50:80 user@jump-host
Local port forwarding allows you to tunnel traffic from a local port to a destination reachable by the SSH server. By mapping a local port to the internal web server's address, you bypass network restrictions imposed by firewalls. This technique is fundamental for pivoting through compromised hosts, enabling tools like Burp Suite or browsers to interact with internal services as if they were running locally, which is vital for further web application vulnerability assessment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ssh -R 8080:192.168.1.50:80 user@jump-host
Why it's wrong here
Remote port forwarding binds a port on the remote SSH server to a local port on your machine. This would open a listener on the jump host rather than your local machine, failing to provide you with local browser access to the specified internal web application on the jump host's network.
- ✗
ssh -D 8080 user@jump-host
Why it's wrong here
Dynamic port forwarding creates a SOCKS proxy. While this would allow you to route traffic through the jump host, it requires additional browser configuration or proxy-aware tools to function correctly. The prompt specifically asks for a standard port mapping approach to access a single service directly through a browser.
- ✓
ssh -L 8080:192.168.1.50:80 user@jump-host
Why this is correct
Local port forwarding uses the -L flag to map a local port (8080) to the destination internal IP and port (192.168.1.50:80). This connection is tunneled through the SSH session, allowing you to access the web application by pointing your local web browser to http://127.0.0.1:8080, effectively bypassing the firewall limitations.
- ✗
ssh -fN -L 192.168.1.50:80:8080 user@jump-host
Why it's wrong here
This syntax incorrectly places the destination IP and port in the source position. In an -L directive, the first port is the local listener. This command would attempt to bind to the internal IP address on your local machine, which is invalid since that IP is not assigned locally.
About these practice questions
One of 285 original PEN-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official OffSec exam blueprint
This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.