Refer to the exhibit. What is the most likely cause of the 'Connection reset by peer' error when using the PsExec module?
This specific error code in the context of PsExec often signals that a security product or the Windows firewall identified the suspicious activity of installing a service remotely and terminated the SMB connection to prevent further compromise, which is standard behavior for modern EDR solutions in a secure environment.
Why this answer
The error 'Connection reset by peer' during a PsExec exploit attempt usually indicates that an active security control, such as a host-based firewall or endpoint protection, terminated the connection. PsExec relies on the Admin$ share and the service control manager. If the target system detects the service installation attempt or the connection from an unauthorized source, it will forcefully drop the connection to block the exploitation attempt, a common scenario in hardened enterprise environments.
Exam trap
Candidates often assume the error is due to a syntax error in the Metasploit module or an invalid payload, ignoring the reality of host-based security blocking SMB administrative shares.