Be able to run msfconsole, search and use modules, set RHOSTS, LHOST, and LPORT correctly, generate payloads with msfvenom, and manage sessions. The critical skill is knowing which host LHOST must reference so the reverse shell returns to your handler.
Start practicing
Metasploit — choose a session length
Free · No account required
Domain overview
This domain covers the Metasploit Framework as used in authorized penetration testing: module selection, payload generation with msfvenom, handler configuration, and post-exploitation session management. GPEN questions test practical command recall—how to background and resume sessions, set LHOST/LPORT for reverse shells, and build encoded payloads that avoid bad characters.
Exam objectives
Using the sessions command and session IDs to interact with or background Meterpreter and shell sessions
Setting LHOST and LPORT so reverse payloads connect back to the tester's listener
Generating Linux ELF and other payloads with msfvenom, including encoder selection
Configuring exploit modules, options, and multi/handler for staged and stageless payloads
Confusing background with exit or Ctrl-Z; candidates forget the session persists and must be resumed with sessions -i
Setting LHOST to the target's address instead of the tester's reachable interface for the reverse connection
Assuming an encoder guarantees AV evasion; encoding primarily removes bad characters and reshapes the payload
Click any question to see the full explanation and answer options, or start a focused practice session above.
Which command in the Metasploit Framework allows a user to interact with a backgrounded session after a successful exploit execution?
2Refer to the exhibit. Why did the EternalBlue exploit attempt fail despite the scanner identifying the target as vulnerable?
3What is the purpose of the 'meterpreter' payload in the Metasploit framework?
4Refer to the exhibit. What is the most likely cause of the 'Connection reset by peer' error when using the PsExec module?
5Which of the following describes the function of the 'msfvenom' tool within the Metasploit ecosystem?
6In Metasploit, what is the significance of the 'LHOST' parameter when setting up a reverse shell?
7When using Metasploit to perform a vulnerability scan, which module type should be selected?
8Refer to the exhibit. Which command allows the tester to switch their interaction focus from session 1 to session 2?
9When a reverse shell connection fails to reach the listener, what is the best first step for troubleshooting?
10During an internal assessment, a tester uses the auxiliary scanner auxiliary/scanner/smb/smb_version and receives the result 'Host is running Windows Server 2016'. The tester then selects exploit/windows/smb/ms17_010_eternalblue but the exploit reports 'The target is not vulnerable'. Which Metasploit feature should the tester use to determine why the exploit check failed and what SMB dialect the target actually supports?
11A penetration tester has just obtained a Meterpreter session on a Linux web server and wants to keep it active while performing other tasks in msfconsole. Which command should the tester issue to return to the msfconsole prompt while leaving the session running in the background?
12A penetration tester uses msfvenom to generate a Linux ELF reverse shell payload. The tester wants the payload to connect back to 192.168.1.50 on port 4444 and to embed an encoder that removes null bytes and other bad characters to survive transmission through a constrained channel. Which msfvenom command line correctly produces this payload?
13A penetration tester needs to generate a standalone Windows executable payload that will connect back to the tester's machine at 10.10.14.5 on port 4444. The tester wants to avoid depending on the Metasploit console during payload generation. Which msfvenom command should be used?
14During a penetration test, a tester obtains a Meterpreter session on a Windows host but the session dies immediately after the initial connection. The tester suspects that the payload is being terminated by endpoint protection. Which Meterpreter feature should the tester use to migrate the session into a more stable process?
15A tester has compromised a Windows host and wants to use Metasploit to harvest credentials from memory without uploading additional tools. Which Metasploit post-exploitation module should be used to extract password hashes from the LSASS process?
Be able to run msfconsole, search and use modules, set RHOSTS, LHOST, and LPORT correctly, generate payloads with msfvenom, and manage sessions. The critical skill is knowing which host LHOST must reference so the reverse shell returns to your handler.
The Courseiva GPEN question bank contains 15 questions in the Metasploit domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Metasploit domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included