During an internal engagement, a penetration tester compromises a vulnerable web server in VLAN 10 and then configures an SSH local port forward so that queries from the tester's laptop are transparently relayed through the web server to a database that only hosts in VLAN 20 can reach. Which hacking concept is the tester applying to reach the protected database segment?
The tester is using pivoting. By turning the compromised web server into an intermediary, all traffic to the database appears to originate from a trusted host in VLAN 10, allowing the attacker to move deeper into the environment. This is not privilege escalation (which raises permission levels on the same host), banner grabbing (which only collects service information), nor session fixation (which targets web authentication tokens). Pivoting is the concept of leveraging control over one system to attack additional internal assets that were previously inaccessible.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is VLAN, and why is it used?
Open an interactive chat with Bash
How does SSH local port forwarding work?
Open an interactive chat with Bash
What are the different types of pivoting in penetration testing?
Open an interactive chat with Bash
What is VLAN and why is it important in networking?
Open an interactive chat with Bash
How does SSH local port forwarding work?
Open an interactive chat with Bash
Can you explain the difference between pivoting and privilege escalation?
Open an interactive chat with Bash
Certified Ethical Hacker (CEH)
Information Security and Ethical Hacking Overview
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .