PT0-002 Attacks and Exploits Practice Question
In Metasploit, after searching for an exploit, you select it with 'use exploit/...' and set required options. What is the final command to execute the exploit against the target?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
run
The 'run' or 'exploit' command launches the exploit.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
execute
Why it's wrong here
The 'execute' command is not part of Metasploit's msfconsole vocabulary. After selecting an exploit module, the framework requires the 'run' command or its alias 'exploit' to trigger the module's execution. Typing 'execute' will be interpreted as an unknown command and will produce an error. This term is often confused with executing shell commands on the target, but that is a separate function performed via payloads or sessions.
- ✗
launch
Why it's wrong here
'launch' is a generic verb for starting a process, but it is not recognized as a command within Metasploit's console. When working with a selected exploit, the user must use 'run' or 'exploit' to execute the module. Since 'launch' is not defined in Metasploit's command parser, it will result in an 'Unknown command' error. This misconception likely arises from general software terminology, but Metasploit has its own specific command set.
- ✗
start
Why it's wrong here
'start' is another common verb that is not part of Metasploit's command set. While many services and applications are started with 'start', Metasploit's msfconsole does not accept this command to launch an exploit. Instead, the user must issue 'run' (or 'exploit') after configuring the module's options. Entering 'start' will be rejected with an error, as Metasploit's command interpreter only recognizes a predefined list of commands.
- ✓
run
Why this is correct
'run' is the correct command to initiate a selected Metasploit exploit. It is also an alias for 'exploit', but 'run' is more versatile and works for both exploit and auxiliary modules. After setting required options like RHOSTS, RPORT, and PAYLOAD, the 'run' command executes the module and establishes the attack as configured. This command is essential in interactive use and in resource scripts for automation.
Go deeper
Related to this question
About these practice questions
One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.