PT0-002 Attacks and Exploits Practice Question
A penetration tester is using Metasploit to pivot from a compromised host to an internal network. Which THREE Metasploit features can facilitate pivoting?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Metasploit route command
The 'route' command adds routes through a session, and Metasploit's socks proxy (auxiliary/server/socks4a) can be used. Autoroute is a post module. Exploit/multi/handler is for reverse shells, not directly for pivoting. Port forwarding via SSH is external to Metasploit.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Exploit/multi/handler
Why it's wrong here
Exploit/multi/handler is the generic payload listener used to receive reverse shells, not a pivoting tool. It merely waits for an inbound connection from a compromised host; it does not alter Metasploit's routing table or create a pathway to subnets behind that host. While a handler is often used in a pivot scenario to catch a shell that is forwarded through a compromised machine, the handler itself provides no routing or proxying capability, so it cannot enable pivoting.
- ✓
Metasploit route command
Why this is correct
The `route` command is the core Metasploit pivot primitive: `route add <subnet> <netmask> <session_id>` tells Metasploit's dispatcher to send any packets destined for that subnet through the specified session, typically a Meterpreter or shell session on a compromised host. This allows all built-in modules (scanners, exploits, auxiliary) to reach otherwise inaccessible internal networks via the session's existing connection. It is a manual, session-dependent routing entry, making it the correct classic answer for Metasploit-based pivoting.
- ✗
SSH local port forwarding
Why it's wrong here
SSH local port forwarding is an external tunneling technique, not a Metasploit feature; Metasploit has no native command to perform SSH local port forwarding. You can run `ssh -L` on the attacker machine to forward a single local port through an SSH server on a compromised host to a target service, but that forwards only one port at a time and is independent of Metasploit's session/routing infrastructure. Since the scenario specifically asks about a Metasploit capability, this option is incorrect.
- ✓
Autoroute post module
Why this is correct
The `post/multi/manage/autoroute` module automates route creation by reading the compromised host's active network interfaces (e.g., via Meterpreter's `route` command) and adding routes for any subnets it sees, such as a second internal NIC. This eliminates the manual step of `route add` and ensures Metasploit modules can immediately reach networks that the target can access. It is a legitimate pivoting technique and correct as an automated alternative to the `route` command.
- ✓
Metasploit socks proxy
Why this is correct
Metasploit's `auxiliary/server/socks_proxy` (and its predecessor socks4a) runs a SOCKS proxy on the attacker's machine and chains traffic through a session, allowing external tools like `proxychains` or `curl` to access the target network via the compromised host. Unlike the `route` command, which only affects Metasploit's internal module traffic, the SOCKS proxy exposes the pivot to any SOCKS-aware utility. This is a valid Metasploit pivot method, distinct from adding routes to the module dispatcher.
Go deeper
Related to this question
Learn chapter
Masscan and ZMap for Fast Port Scanning
Key term
Metasploit
Metasploit is a powerful penetration testing framework that helps security professionals find and exploit vulnerabilities in computer systems.
Key term
Pivoting
Pivoting is a post-exploitation technique where an attacker uses a compromised system as a relay to access other systems on a network that were not directly reachable.
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.