Courseiva
Attacks and Exploits →mediumMultiple Choice

PT0-002 Attacks and Exploits Practice Question

A tester runs the following Metasploit commands: ``` msf6 > use exploit/multi/handler msf6 exploit(multi/handler) > set PAYLOAD windows/meterpreter/reverse_tcp msf6 exploit(multi/handler) > set LHOST 10.0.0.5 msf6 exploit(multi/handler) > set LPORT 4444 msf6 exploit(multi/handler) > run ``` What is the purpose of this configuration?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To receive a reverse shell from a target that already executed the payload

The multi/handler is a generic handler used to receive reverse connections from payloads that were delivered separately (e.g., via phishing). It waits for the target to connect back.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To exploit a remote service directly

    Why it's wrong here

    The multi/handler module is purely a listener; it does not send any exploit code or attempt to trigger a vulnerability in a target service. To exploit a remote service directly, you would need to run an exploit module (e.g., exploit/windows/smb/ms17_010_eternalblue) which delivers the attack against the specific service. The multi/handler has no capability to probe, fuzz, or interact with a service to achieve code execution; it only waits for a connection from a payload that has already run on the target. Therefore, this choice misunderstands the distinct roles of exploit and payload handling in Metasploit.

  • ✓

    To receive a reverse shell from a target that already executed the payload

    Why this is correct

    This is the correct function: multi/handler acts as a listener that waits for a reverse TCP connection from a target that has already executed a Meterpreter or other reverse payload. In a typical attack workflow, the tester starts this handler on their machine, then delivers a payload to the target via phishing, exploit, or direct execution; once the target runs the payload, it connects back to the handler's listening port. The handler then provides an interactive session (e.g., Meterpreter) for post-exploitation. It is a generic catch-all for reverse shells and is indispensable when using staged payloads, where the initial stager connects back to fetch the full payload.

  • ✗

    To perform a bind shell attack

    Why it's wrong here

    A bind shell attack requires the target to open a listening port and the attacker to actively connect to it, using a payload like windows/meterpreter/bind_tcp. The multi/handler, however, is configured to listen on a local port for an incoming connection—it does not initiate outbound connections to a target. Thus, if you ran a bind payload, you would need to connect to the target's IP and port directly with a client like netcat or via an exploit module that sets up the bind payload and hands you a session. The multi/handler cannot be repurposed to connect to a bind shell; it expects the target to dial in, which is the opposite direction of traffic flow.

  • ✗

    To stage a payload for later execution

    Why it's wrong here

    Staging in Metasploit refers to the process where a small stager payload is first sent to the target, and then that stager downloads the full, larger payload from the attacker—typically using multi-stage payloads like windows/meterpreter/reverse_tcp. The multi/handler is not the mechanism that stages payloads; it is the server-side listener that catches the connection after the staging and execution have occurred. You would use msfvenom to generate a staged payload, deliver it to the target, and then rely on multi/handler to receive the final session—not to stage or push the payload itself. Therefore, this option confuses the listener role with the payload generation/delivery stage.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.