mediumMultiple Choice
PT0-002 Practice Question: A penetration tester is analyzing a Ruby script…
A penetration tester is analyzing a Ruby script that uses the 'metasploit-framework' gem. The script includes a line: `Msf::Simple::Framework.create` and then calls `run_single('use exploit/multi/handler')`. What is the primary purpose of this script?
⚠ Common exam trap
Test-takers frequently confuse the `use exploit/multi/handler` command with a generic exploit or attack automation, when in fact it is purely a listener for incoming reverse connections, not an active exploit or scanning tool.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set up a Metasploit payload handler to catch reverse shells
The script uses `Msf::Simple::Framework.create` to instantiate a Metasploit Framework instance and then calls `run_single('use exploit/multi/handler')` to load the multi/handler module. This module is specifically designed to listen for incoming connections from payloads (e.g., reverse shells) that have been executed on a target, making the script's primary purpose to set up a handler to catch reverse shells.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Automate a port scan across multiple targets
Why it's wrong here
The multi/handler module is strictly a payload listener; it contains no scanning logic and is not designed to enumerate open ports or hosts. Port scanning in Metasploit is performed by auxiliary modules such as scanner/portscan/tcp, which are invoked with the run command after setting RHOSTS and THREADS. A Ruby script that instantiates multi/handler would only open a local listening socket, making it useless for automation of port scans across multiple targets.
- ✓
Set up a Metasploit payload handler to catch reverse shells
Why this is correct
This is exactly the intended function of the multi/handler module: it acts as a generic payload handler that waits for a reverse connection from an exploited target. By instantiating Msf::Exploit::Remote::MultiHandler in Ruby, setting a payload (e.g., windows/meterpreter/reverse_tcp) and binding to an LHOST/LPORT, the script establishes a listener that captures incoming sessions for post-exploitation. This is a common programmatic way to set up a handler outside the interactive msfconsole, especially when automating staged payload delivery or managing multiple listeners concurrently.
- ✗
Create a Metasploit resource script for automated attacks
Why it's wrong here
Resource scripts are separate .rc files that contain msfconsole commands to be executed sequentially, such as 'use exploit/multi/handler', 'set PAYLOAD ...', and 'exploit -j'. A Ruby script that directly uses the multi/handler class does not create a resource script; it bypasses msfconsole entirely and invokes the framework's Ruby API to configure and start the handler programmatically. While the end result can be similar, the vector of execution is different: one is command-driven, the other is code-driven, and this question specifically examines the Ruby script technique.
- ✗
Load and execute a local exploit against a specified target
Why it's wrong here
Executing a local exploit requires an exploit module, such as exploit/windows/local/xxx, which contains vulnerability-specific code, target enumeration, and a defined exploit method. The multi/handler module is not an exploit; it lacks any vulnerability knowledge or target addressing, and its purpose is solely to listen for and manage payload sessions after exploitation has already occurred. In Ruby scripts, local exploits are loaded and run using the framework's run_single with a full exploit module path, never through multi/handler, which would simply sit idle waiting for a connection that cannot be initiated by itself.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.