GPEN Metasploit Practice Question
Exhibit
msf6 > search type:exploit platform:windows smb msf6 > use exploit/windows/smb/ms17_010_eternalblue msf6 exploit(windows/smb/ms17_010_eternalblue) > set RHOSTS 192.168.1.50 msf6 exploit(windows/smb/ms17_010_eternalblue) > exploit [*] Started reverse TCP handler on 192.168.1.10:4444 [*] 192.168.1.50:445 - Using auxiliary/scanner/smb/smb_ms17_010 as check [*] 192.168.1.50:445 - Host is likely VULNERABLE to MS17-010! [*] 192.168.1.50:445 - Scanned 1 of 1 hosts (1 succeeded to be vulnerable) [*] 192.168.1.50:445 - Starting exploit [!] Error: Exploit failed: The target is not exploitable.
Refer to the exhibit. Why did the EternalBlue exploit attempt fail despite the scanner identifying the target as vulnerable?
⚠ Common exam trap
Candidates often assume that a positive vulnerability scan guarantees successful exploitation, forgetting that runtime environmental factors like patches, AV, or memory protections can crash payloads.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The target environment rejected the payload execution
The exhibit shows the module successfully detected vulnerability but failed exploitation. This often occurs due to differences in the target's operating system build, unexpected memory protection, or a race condition where the service crashed during the initial check. In professional testing, this highlights the instability of kernel-level exploits. Even if a target appears vulnerable, environmental variables like patches, antivirus interference, or DEP/ASLR settings can prevent the shellcode from executing correctly in memory.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The RHOSTS value is configured incorrectly
Why it's wrong here
The RHOSTS value is clearly set to the target IP address. The scanner successfully connected to that IP and confirmed the vulnerability. Therefore, the connection is not the issue; the failure resides within the exploit payload's interaction with the target's specific system state during the final execution phase.
- ✗
The exploit module requires an active session
Why it's wrong here
Exploit modules like EternalBlue are designed to create the initial session, not rely on existing ones. Requiring an active session before running this module is illogical. The error message indicates a failure to trigger the vulnerability, which is a common occurrence with complex memory-corruption exploits in production environments.
- ✓
The target environment rejected the payload execution
Why this is correct
Even if the target is vulnerable, the exploit might fail due to environmental factors like antivirus, system stability, or specific patch levels not caught by the scanner. This is a common real-world failure mode where the vulnerability check passes, but the actual payload delivery or execution is blocked by security controls.
- ✗
The listener port is already in use by another process
Why it's wrong here
If the listener port were in use, Metasploit would throw a specific socket binding error immediately upon starting the exploit. The output shows the listener started successfully, meaning the conflict is not with the local network configuration but with the target's response to the exploit attempt itself.
About these practice questions
Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.