Courseiva
Metasploit →mediumMultiple Choice

GPEN Metasploit Practice Question

Which command in the Metasploit Framework allows a user to interact with a backgrounded session after a successful exploit execution?

⚠ Common exam trap

Candidates often confuse the 'sessions -i' command with 'exploit' or 'connect', mistakenly believing that they need to re-run the exploit to regain access to a backgrounded session.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

sessions -i

The 'sessions' command is the primary method for managing active connections within Metasploit. Once an exploit establishes a payload, the session moves to the background. Using 'sessions -i <id>' connects the user to the specific meterpreter shell, enabling post-exploitation activities. This is crucial for maintaining persistence and executing lateral movement tasks in a penetration test, as it allows the operator to toggle between multiple compromised targets effectively.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    exploit -j

    Why it's wrong here

    The -j flag runs an exploit as a background job, but it does not interact with existing sessions. While it prevents the console from being blocked by a specific task, it does not provide the interactive command line interface necessary to control the compromised host after the initial payload activation.

  • ✓

    sessions -i

    Why this is correct

    The sessions command with the -i flag followed by the ID number is the standard syntax for interacting with a specific established Meterpreter session. It transfers the console's input/output to the remote system, allowing the tester to execute commands directly on the target machine with the payload's privileges.

  • ✗

    run -s

    Why it's wrong here

    The run command is typically used to execute internal scripts or modules against a session, but it is not the mechanism for switching the console focus to an interactive session. Using this flag incorrectly will likely result in an error as the console expects specific module arguments instead.

  • ✗

    use -session

    Why it's wrong here

    There is no 'use -session' command in Metasploit. The 'use' command is exclusively reserved for selecting exploit, auxiliary, or post modules. Attempting to use this syntax will return a module not found error because the framework does not recognize this as a valid session management directive.

About these practice questions

This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.