GPEN · domain
Metasploit
This domain covers the Metasploit Framework as used in authorized penetration testing: module selection, payload generation with msfvenom, handler configuration, and post-exploitation session management. GPEN questions test practical command recall—how to background and resume sessions, set LHOST/LPORT for reverse shells, and build encoded payloads that avoid bad characters.
Focused practice
Practice Metasploit questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Metasploit
Be able to run msfconsole, search and use modules, set RHOSTS, LHOST, and LPORT correctly, generate payloads with msfvenom, and manage sessions. The critical skill is knowing which host LHOST must reference so the reverse shell returns to your handler.
Using the sessions command and session IDs to interact with or background Meterpreter and shell sessions
Setting LHOST and LPORT so reverse payloads connect back to the tester's listener
Generating Linux ELF and other payloads with msfvenom, including encoder selection
Configuring exploit modules, options, and multi/handler for staged and stageless payloads
Watch out for
Common Metasploit exam traps
- ▸Confusing background with exit or Ctrl-Z; candidates forget the session persists and must be resumed with sessions -i
- ▸Setting LHOST to the target's address instead of the tester's reachable interface for the reverse connection
- ▸Assuming an encoder guarantees AV evasion; encoding primarily removes bad characters and reshapes the payload
Question index
All Metasploit questions (15)
Click any question to see the full explanation, or start a practice session above.
Refer to the exhibit. What is the most likely cause of the 'Connection reset by peer' error when using the PsExec module?
Hard2During an internal assessment, a tester uses the auxiliary scanner auxiliary/scanner/smb/smb_version and receives the result 'Host is running Windows Server 2016'. The tester then selects exploit/windows/smb/ms17_010_eternalblue but the exploit reports 'The target is not vulnerable'. Which Metasploit feature should the tester use to determine why the exploit check failed and what SMB dialect the target actually supports?
Hard3Which of the following describes the function of the 'msfvenom' tool within the Metasploit ecosystem?
Medium4What is the purpose of the 'meterpreter' payload in the Metasploit framework?
Easy5When a reverse shell connection fails to reach the listener, what is the best first step for troubleshooting?
Hard6A penetration tester uses msfvenom to generate a Linux ELF reverse shell payload. The tester wants the payload to connect back to 192.168.1.50 on port 4444 and to embed an encoder that removes null bytes and other bad characters to survive transmission through a constrained channel. Which msfvenom command line correctly produces this payload?
Hard7Refer to the exhibit. Why did the EternalBlue exploit attempt fail despite the scanner identifying the target as vulnerable?
Medium8In Metasploit, what is the significance of the 'LHOST' parameter when setting up a reverse shell?
Easy9When using Metasploit to perform a vulnerability scan, which module type should be selected?
Medium10A penetration tester needs to generate a standalone Windows executable payload that will connect back to the tester's machine at 10.10.14.5 on port 4444. The tester wants to avoid depending on the Metasploit console during payload generation. Which msfvenom command should be used?
Easy11Refer to the exhibit. Which command allows the tester to switch their interaction focus from session 1 to session 2?
Medium12Which command in the Metasploit Framework allows a user to interact with a backgrounded session after a successful exploit execution?
Medium13A tester has compromised a Windows host and wants to use Metasploit to harvest credentials from memory without uploading additional tools. Which Metasploit post-exploitation module should be used to extract password hashes from the LSASS process?
Medium14During a penetration test, a tester obtains a Meterpreter session on a Windows host but the session dies immediately after the initial connection. The tester suspects that the payload is being terminated by endpoint protection. Which Meterpreter feature should the tester use to migrate the session into a more stable process?
Hard15A penetration tester has just obtained a Meterpreter session on a Linux web server and wants to keep it active while performing other tasks in msfconsole. Which command should the tester issue to return to the msfconsole prompt while leaving the session running in the background?
EasyOther domains
All GPEN exam domains
Frequently asked questions
- What does the Metasploit domain cover on the GPEN exam?
- Be able to run msfconsole, search and use modules, set RHOSTS, LHOST, and LPORT correctly, generate payloads with msfvenom, and manage sessions. The critical skill is knowing which host LHOST must reference so the reverse shell returns to your handler.
- How many questions are in this domain?
- This page lists all 15 Metasploit questions in the GPEN question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Metasploit questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.