PT0-002 Vulnerability Discovery and Analysis Practice Question
A penetration tester wants to exploit a Windows system using a known vulnerability and gain a meterpreter session. Which tool is most appropriate?
⚠ Common exam trap
Candidates often confuse tools used for post-exploitation or credential attacks (CrackMapExec, Hydra) with the actual exploit delivery framework (Metasploit) required to gain a Meterpreter session from a known vulnerability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Metasploit Framework
Metasploit Framework (B) is the most appropriate tool because it provides a comprehensive exploit development and execution environment, including pre-built modules for known Windows vulnerabilities and seamless integration with Meterpreter payloads. Unlike the other options, Metasploit is specifically designed to deliver a Meterpreter session after exploitation, handling payload generation, staging, and post-exploitation tasks natively.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
CrackMapExec
Why it's wrong here
CrackMapExec is a post-exploitation and network enumeration suite that operates over SMB, LDAP, WinRM, and other protocols to gather information, dump credentials, and execute commands with existing credentials. It does not contain vulnerability exploits or payload delivery mechanisms, so it cannot be used to initially compromise an unauthenticated Windows system. Its value emerges only after a foothold exists, making it a lateral movement tool rather than an exploitation tool.
- ✓
Metasploit Framework
Why this is correct
The Metasploit Framework is a comprehensive exploitation platform that ships with hundreds of ready-to-use exploits, payloads, encoders, and auxiliary modules. For Windows, it can target specific Common Vulnerabilities and Exposures (CVEs) such as MS17-010 EternalBlue or SMBv2 exploits and deliver a Meterpreter payload to establish a command-and-control session. It is purpose-built for the exploitation phase, directly triggering a vulnerability to gain initial code execution on the target.
- ✗
Impacket
Why it's wrong here
Impacket is a collection of Python classes and scripts for crafting and manipulating network protocols such as SMB, MSRPC, Kerberos, and LDAP. Tools like psexec.py or wmiexec.py can execute commands on remote Windows systems, but they require pre-existing valid credentials or a captured hash and do not exploit any software vulnerability. Impacket focuses on protocol-level interaction and post-exploitation, not on providing exploit code for initial system compromise.
- ✗
Hydra
Why it's wrong here
Hydra is an online password guessing and brute-force tool that attempts to discover weak credentials by rapidly testing username/password combinations against services like SMB, SSH, and RDP. It does not target or corrupt software flaws; instead, it relies on authentication weaknesses and the failure of account lockout policies. Hydra can be part of an attack chain, but it is not an exploitation tool and cannot exploit a Windows system without valid credentials.
Go deeper
Related to this question
Learn chapter
Exploit Frameworks: Core Impact and Canvas
Key term
Post-exploitation
Post-exploitation is the phase of a penetration test that begins after an attacker has gained initial access to a system, focusing on maintaining access, escalating privileges, moving laterally, and achieving the test's objectives.
Key term
Meterpreter
Meterpreter is an advanced, dynamically extensible payload that provides an interactive command shell and post-exploitation capabilities within a memory-resident environment during a penetration test.
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.