Exploitation with Metasploit Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Exploitation with Metasploit flashcards as text
Which Metasploit command searches for modules by CVE number or keyword?
Answer: search
The 'search' command in msfconsole lets you find modules by CVE, name, platform, or type.
What does the 'check' command do in Metasploit before running an exploit?
Answer: Verifies the target is vulnerable without exploiting it
The 'check' command tests whether the target is vulnerable without actually launching the exploit.
Which payload type in Metasploit establishes a persistent TCP connection from target back to attacker?
Answer: reverse/tcp
A reverse_tcp payload causes the target machine to connect back to the attacker's listener.
In Metasploit, what is the purpose of the LHOST option?
Answer: The local attacker machine IP that receives the reverse connection
LHOST specifies the attacker's IP address where reverse payloads will connect back to.
What Metasploit command shows all currently configured options for the selected module?
Answer: show options
'show options' displays all required and optional parameters for the active module along with their current values.
Which msfvenom flag specifies the output format for a generated payload?
Answer: -f
The -f flag in msfvenom specifies the output format such as exe, elf, raw, or python.
What happens when you run 'sessions -i 1' in Metasploit?
Answer: Interacts with session number 1
'sessions -i 1' interacts with (drops into) the active session with ID 1.