โ† All EJPT Flashcard Decks

Exploitation with Metasploit Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Exploitation with Metasploit flashcards as text
  1. Which Meterpreter command uploads a file from the attacker to the compromised target?

    Answer: upload

    The 'upload' command transfers files from the attacker's machine to the target system.

  2. What does 'getsystem' attempt to do in a Meterpreter session?

    Answer: Escalate privileges to SYSTEM level

    'getsystem' tries multiple privilege escalation techniques to gain SYSTEM-level access on Windows.

  3. Which Meterpreter command captures a screenshot of the target's desktop?

    Answer: screenshot

    The 'screenshot' command in Meterpreter takes a snapshot of the target's current desktop.

  4. What is the purpose of 'hashdump' in Meterpreter?

    Answer: Dump password hashes from the SAM database

    'hashdump' extracts NTLM password hashes from the Windows SAM database for offline cracking.

  5. In Metasploit, which module type is used after gaining access to perform further actions on the target?

    Answer: post

    Post modules run after a successful exploitation to perform tasks like privilege escalation, persistence, or data gathering.

  6. What does the 'background' command do in an active Meterpreter session?

    Answer: Sends the session to the background while keeping it alive

    'background' returns to the msfconsole prompt while keeping the Meterpreter session open and accessible.

  7. Which command in msfconsole sets a global option that applies to all subsequently loaded modules?

    Answer: setg

    'setg' (set global) persists an option like LHOST or LPORT across all modules without needing to re-enter it.