CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium

A tester generates a reverse shell payload using msfvenom targeting a Windows host and configures a listener before delivering the payload. Which Metasploit component must the tester configure to receive the incoming connection once the payload executes?

  1. Aexploit/multi/handler
  2. Bpost/windows/gather module
  3. Cauxiliary/scanner module
  4. Dencoder module
Show answer & explanation

Correct answer: A. exploit/multi/handler

The exploit/multi/handler module is used in Metasploit to set up a listener that matches the payload type, LHOST, and LPORT configured in the msfvenom-generated payload, allowing the tester to catch the reverse connection.

Why the other options are wrong

  • B. Post-exploitation gather modules run after a session is established, not to catch the initial connection.
  • C. Auxiliary scanner modules are used for reconnaissance, not catching shells.
  • D. Encoder modules obfuscate payloads to evade detection, not handle connections.

Metasploit Multi/Handler

A Metasploit module used to set up a listener that matches a standalone payload (e.g., generated by msfvenom) to catch the resulting session.

  • Must match payload type, LHOST, and LPORT exactly
  • Commonly used with msfvenom-generated standalone payloads
  • Run within msfconsole using exploit/multi/handler

Memory trick: Handler is the catcher's mitt waiting for the pitched payload.

More Attacks and Exploits questions