GPEN Escalation and Exploitation Practice Question
You have obtained a Meterpreter session on a Windows 10 host as a standard user. You want to escalate privileges by exploiting a vulnerable kernel driver. Which Metasploit module category would you use to search for suitable exploits?
⚠ Common exam trap
A common mix-up: candidates confuse remote exploit categories with local privilege escalation modules, which are distinctly separated in Metasploit's directory structure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
exploit/windows/local
Local privilege escalation exploits in Metasploit are found under the 'exploit/windows/local' category. These modules are specifically designed to run within a session and elevate privileges by exploiting vulnerabilities such as kernel driver flaws. Other categories like SMB, RDP, or HTTP are for remote exploitation and do not apply when you already have local access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
exploit/windows/rdp
Why it's wrong here
The 'exploit/windows/rdp' category contains exploits targeting Remote Desktop Protocol services, which are used for remote access. These are not local privilege escalation modules and would not be executed within a local session. They are designed for remote exploitation of RDP vulnerabilities, not for escalating privileges on a host where you already have a foothold.
- ✗
exploit/windows/smb
Why it's wrong here
The 'exploit/windows/smb' category contains exploits that target the SMB protocol, often for remote code execution or information disclosure. These are not local privilege escalation exploits and typically require network access to the target. They would not help you escalate privileges from an existing local session. Using SMB exploits would be inappropriate for this scenario.
- ✓
exploit/windows/local
Why this is correct
The 'exploit/windows/local' category contains local privilege escalation exploits for Windows, including kernel driver vulnerabilities. These modules are designed to run within an existing session to elevate privileges. By searching this category, you can find exploits that match the target's architecture and patch level. This is the correct place to look for kernel-based escalation modules in Metasploit.
- ✗
exploit/windows/http
Why it's wrong here
The 'exploit/windows/http' category contains exploits for web servers or applications running on Windows. These are remote exploits, not local privilege escalation modules. They would not be useful for escalating privileges from a local user session. Searching this category would not yield kernel driver exploits suitable for your goal.
About these practice questions
This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.