Courseiva

PEN-200 Port Redirection and Tunneling Practice Question

You have gained a foothold on an internal Linux host (10.10.10.20) that can reach a segregated network containing a web server at 192.168.100.50:80. Your attack machine cannot reach 192.168.100.50 directly. You want to use the compromised host to forward traffic from your machine's local port 8080 to 192.168.100.50:80. Which SSH command should you run from your attack machine?

⚠ Common exam trap

Test-takers frequently confuse local and remote port forwarding: remembering that -L forwards local traffic to a remote destination, while -R does the opposite, is crucial.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ssh -L 8080:192.168.100.50:80 user@10.10.10.20

To reach an internal service through a compromised host, you use SSH local port forwarding. The -L option binds a local port on your machine and tunnels connections through the SSH server to the specified destination. The correct syntax maps local port 8080 to 192.168.100.50:80 via the pivot host. This allows you to access the internal web server by connecting to localhost:8080.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ssh -D 8080 user@10.10.10.20

    Why it's wrong here

    Dynamic port forwarding (-D) creates a SOCKS proxy on your local port 8080, but it does not directly map to a specific internal host and port. You would need to configure a SOCKS-aware client to route traffic through it, rather than simply connecting to localhost:8080 as a direct forward.

  • ✗

    ssh -L 80:192.168.100.50:8080 user@10.10.10.20

    Why it's wrong here

    This command forwards local port 80 to 192.168.100.50:8080. It reverses the ports: the internal web server listens on port 80, not 8080, and binding local port 80 may require elevated privileges. It would not correctly forward traffic to the web service.

  • ✗

    ssh -R 8080:192.168.100.50:80 user@10.10.10.20

    Why it's wrong here

    Remote port forwarding (-R) makes the remote SSH server listen on a port and forward connections back to your local machine. That would expose a service on your machine to the internal network, not allow you to reach the internal web server from your attack box.

  • ✓

    ssh -L 8080:192.168.100.50:80 user@10.10.10.20

    Why this is correct

    This command creates a local port forward: it listens on your local port 8080 and forwards connections through the SSH tunnel to 192.168.100.50:80 from the perspective of the compromised host. This is exactly what is needed to reach the internal web server via the pivot.

About these practice questions

Courseiva writes every PEN-200 question from scratch — 285 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official OffSec exam blueprint

This PEN-200 practice question is part of Courseiva's free OffSec certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PEN-200 exam.