GPEN Metasploit Practice Question
During an internal assessment, a tester uses the auxiliary scanner auxiliary/scanner/smb/smb_version and receives the result 'Host is running Windows Server 2016'. The tester then selects exploit/windows/smb/ms17_010_eternalblue but the exploit reports 'The target is not vulnerable'. Which Metasploit feature should the tester use to determine why the exploit check failed and what SMB dialect the target actually supports?
⚠ Common exam trap
The trap here is believing a version scanner's output is sufficient to predict exploit success, when the exploit's own check method provides the dialect and failure reasons needed for diagnosis.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run the exploit module's check method and then inspect the module's verbose output for the SMB dialect and error details
Exploit modules include a check method that returns a status and, with Verbose enabled, prints the negotiated SMB dialect and the reason the target failed the vulnerability test. Running check and reading that output directly explains the mismatch between the scanner result and the exploit check. Forcing the exploit or running another scanner does not surface the underlying diagnostic detail.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Run the exploit module's check method and then inspect the module's verbose output for the SMB dialect and error details
Why this is correct
Metasploit exploit modules implement a check method that returns a vulnerability status and often prints detailed diagnostic messages when Verbose is enabled. Running check and reviewing the verbose output reveals the SMB dialect negotiated and the specific reason the check failed, such as a missing patch or unsupported dialect. This directly answers both what dialect is in use and why the exploit check failed.
- ✗
Switch to auxiliary/scanner/smb/smb_ms17_010 and review its output
Why it's wrong here
The smb_ms17_010 auxiliary scanner also checks for the MS17-010 vulnerability and can confirm exposure, but it does not explain why the exploit module's check failed or report the negotiated SMB dialect in the same diagnostic detail. It duplicates the check rather than providing the deeper reasoning. The tester needs the exploit module's own check output, not another scanner's verdict.
- ✗
Use the smb_version scanner with the SMB2 option disabled to force SMB1 negotiation
Why it's wrong here
Disabling SMB2 would restrict negotiation but would not provide a diagnostic explanation of the exploit check failure. It may also produce misleading results if the target supports both dialects. The scanner reports version information, not why a specific exploit's check returned not vulnerable. This does not satisfy the requirement to understand the check failure.
- ✗
Run the exploit with the ForceExploit advanced option set to true
Why it's wrong here
ForceExploit bypasses the vulnerability check and attempts the exploit regardless of the check result. It does not explain why the check failed and risks crashing or destabilizing the target. The tester needs diagnostic information about SMB dialect and patch state, not a blind attempt that ignores the safety check. This option addresses neither the 'why' nor the dialect question.
About these practice questions
One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.