GPEN › Metasploit
This domain covers the Metasploit Framework as used in authorized penetration testing: module selection, payload generation with msfvenom, handler configuration, and post-exploitation session management. GPEN questions test practical command recall—how to background and resume sessions, set LHOST/LPORT for reverse shells, and build encoded payloads that avoid bad characters.
GPEN Metasploit — All 29 Questions
Every question in this domain with answers and detailed explanations.
Attacking Password Hashes
Password Attacks and Formats
Scanning and Host Discovery
Vulnerability Scanning
Kerberos Attacks
Reconnaissance
Command and Control
Exploitation Fundamentals
Azure AD Integration
Domain Escalation and Persistence
Azure Apps and Attacks
Escalation and Exploitation
Advanced Password Attacks
Pen Test Planning