Courseiva
Attacks and Exploits →easyMultiple Choice

PT0-002 Attacks and Exploits Practice Question

A penetration tester wants to use Metasploit to exploit a remote service. After selecting an exploit module, which command is used to set the remote host IP address?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

set RHOSTS

In Metasploit, 'set RHOSTS' is used to specify the target IP address.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    set LHOST

    Why it's wrong here

    set LHOST is incorrect because this option defines the local IP address of the attacker's machine, which a reverse payload uses as the callback destination. It does not specify the target system to be exploited; that role belongs to RHOSTS. In a remote exploit scenario, you still need LHOST for a reverse shell, but failing to set RHOSTS means Metasploit has no target address to connect to.

  • ✓

    set RHOSTS

    Why this is correct

    set RHOSTS is the correct command because it assigns the remote system's IP address or hostname that the exploit module will attack. This is a required option for essentially every remote exploit in Metasploit, and it can accept a single address, a CIDR range, or a list. Without RHOSTS, the module cannot initiate a connection to the victim, making all other payload settings meaningless.

  • ✗

    set TARGET

    Why it's wrong here

    set TARGET is not valid for specifying the victim's IP because TARGET selects which platform-specific build of the exploit to use, such as a particular Windows version or service pack. This value is typically chosen from the module's 'show targets' output and is an integer index or a named target string. It controls exploitation logic, not network addressing, so it has no effect on which remote host is contacted.

  • ✗

    set LPORT

    Why it's wrong here

    set LPORT is wrong here because LPORT configures the local port on the attacker's machine that a reverse connection will try to reach, and it is part of the payload's connection settings. It does not identify the remote host at all; instead, it goes hand-in-hand with LHOST for reverse payloads. The remote port and address of the target are configured with RPORT and RHOSTS, respectively.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.