GPEN Metasploit Practice Question
When a reverse shell connection fails to reach the listener, what is the best first step for troubleshooting?
⚠ Common exam trap
Candidates often jump to complex conclusions like firewall rules or payload encoding issues before verifying the most basic requirement: is the listener actually running and reachable?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check local listener status and connectivity
Network connectivity issues are the most common reason for failed exploitation. Verifying the listener configuration and ensuring the target can actually reach the attacker's IP is the logical starting point. Using tools like 'netcat' to test the connectivity or verifying the LHOST settings ensures that the issue is not a simple misconfiguration, which saves significant time during a penetration test by eliminating basic networking errors before checking for complex security controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Re-run the exploit with a different payload
Why it's wrong here
Changing the payload is a reactive approach that doesn't address the underlying networking problem. If the connection cannot be established, changing the payload will likely yield the same result. The best approach is to verify network connectivity and listener configuration before blindly changing modules and wasting effort on ineffective troubleshooting.
- ✓
Check local listener status and connectivity
Why this is correct
The first step in troubleshooting is to ensure the listener is actually running and reachable. Checking if the LHOST is correct and if there is a firewall blocking the LPORT on the attacker's side is crucial, as this is the most common cause of failed reverse connections in laboratory environments.
- ✗
Upgrade the Metasploit framework
Why it's wrong here
While keeping the framework updated is best practice, it is rarely the cause of a specific connection failure. Updating Metasploit takes time and introduces new variables, making it a poor first-line troubleshooting step for connectivity issues that are usually caused by misconfigurations in the local network environment or listener settings.
- ✗
Restart the target machine
Why it's wrong here
Restarting the target machine is invasive and likely to be noticed by monitoring tools. It should never be the first step in troubleshooting connectivity. In professional penetration tests, stability is key, and performing unauthorized reboots can lead to service downtime, which is often forbidden by the rules of engagement.
About these practice questions
This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.