Courseiva

GPEN · domain

Metasploit

This domain covers the Metasploit Framework as used in authorized penetration testing: module selection, payload generation with msfvenom, handler configuration, and post-exploitation session management. GPEN questions test practical command recall—how to background and resume sessions, set LHOST/LPORT for reverse shells, and build encoded payloads that avoid bad characters.

15 questions4 easy6 medium5 hard

Focused practice

Practice Metasploit questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Metasploit

Be able to run msfconsole, search and use modules, set RHOSTS, LHOST, and LPORT correctly, generate payloads with msfvenom, and manage sessions. The critical skill is knowing which host LHOST must reference so the reverse shell returns to your handler.

Using the sessions command and session IDs to interact with or background Meterpreter and shell sessions

Setting LHOST and LPORT so reverse payloads connect back to the tester's listener

Generating Linux ELF and other payloads with msfvenom, including encoder selection

Configuring exploit modules, options, and multi/handler for staged and stageless payloads

Watch out for

Common Metasploit exam traps

  • ▸Confusing background with exit or Ctrl-Z; candidates forget the session persists and must be resumed with sessions -i
  • ▸Setting LHOST to the target's address instead of the tester's reachable interface for the reverse connection
  • ▸Assuming an encoder guarantees AV evasion; encoding primarily removes bad characters and reshapes the payload

Question index

All Metasploit questions (15)

Click any question to see the full explanation, or start a practice session above.

1

Refer to the exhibit. What is the most likely cause of the 'Connection reset by peer' error when using the PsExec module?

Hard
2

During an internal assessment, a tester uses the auxiliary scanner auxiliary/scanner/smb/smb_version and receives the result 'Host is running Windows Server 2016'. The tester then selects exploit/windows/smb/ms17_010_eternalblue but the exploit reports 'The target is not vulnerable'. Which Metasploit feature should the tester use to determine why the exploit check failed and what SMB dialect the target actually supports?

Hard
3

Which of the following describes the function of the 'msfvenom' tool within the Metasploit ecosystem?

Medium
4

What is the purpose of the 'meterpreter' payload in the Metasploit framework?

Easy
5

When a reverse shell connection fails to reach the listener, what is the best first step for troubleshooting?

Hard
6

A penetration tester uses msfvenom to generate a Linux ELF reverse shell payload. The tester wants the payload to connect back to 192.168.1.50 on port 4444 and to embed an encoder that removes null bytes and other bad characters to survive transmission through a constrained channel. Which msfvenom command line correctly produces this payload?

Hard
7

Refer to the exhibit. Why did the EternalBlue exploit attempt fail despite the scanner identifying the target as vulnerable?

Medium
8

In Metasploit, what is the significance of the 'LHOST' parameter when setting up a reverse shell?

Easy
9

When using Metasploit to perform a vulnerability scan, which module type should be selected?

Medium
10

A penetration tester needs to generate a standalone Windows executable payload that will connect back to the tester's machine at 10.10.14.5 on port 4444. The tester wants to avoid depending on the Metasploit console during payload generation. Which msfvenom command should be used?

Easy
11

Refer to the exhibit. Which command allows the tester to switch their interaction focus from session 1 to session 2?

Medium
12

Which command in the Metasploit Framework allows a user to interact with a backgrounded session after a successful exploit execution?

Medium
13

A tester has compromised a Windows host and wants to use Metasploit to harvest credentials from memory without uploading additional tools. Which Metasploit post-exploitation module should be used to extract password hashes from the LSASS process?

Medium
14

During a penetration test, a tester obtains a Meterpreter session on a Windows host but the session dies immediately after the initial connection. The tester suspects that the payload is being terminated by endpoint protection. Which Meterpreter feature should the tester use to migrate the session into a more stable process?

Hard
15

A penetration tester has just obtained a Meterpreter session on a Linux web server and wants to keep it active while performing other tasks in msfconsole. Which command should the tester issue to return to the msfconsole prompt while leaving the session running in the background?

Easy

Frequently asked questions

What does the Metasploit domain cover on the GPEN exam?
Be able to run msfconsole, search and use modules, set RHOSTS, LHOST, and LPORT correctly, generate payloads with msfvenom, and manage sessions. The critical skill is knowing which host LHOST must reference so the reverse shell returns to your handler.
How many questions are in this domain?
This page lists all 15 Metasploit questions in the GPEN question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Metasploit questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
giac-gpen GIAC-GPEN metasploit Practice Questions