CompTIA PenTest+ (PT0-003)Vulnerability Discovery and AnalysisHard
A penetration tester receives a vulnerability scan report indicating a Windows host is vulnerable to MS17-010 (EternalBlue). Before launching an exploit, the tester wants to non-intrusively confirm the vulnerability using Metasploit. Which type of module should the tester run first?
- AAn auxiliary scanner module, such as auxiliary/scanner/smb/smb_ms17_010
- BA post-exploitation module for privilege escalation
- CA payload generator using msfvenom
- DAn exploit module, such as exploit/windows/smb/ms17_010_eternalblue
Show answer & explanationAnswer & explanation
Correct answer: A. An auxiliary scanner module, such as auxiliary/scanner/smb/smb_ms17_010
Auxiliary scanner modules in Metasploit are designed to verify conditions (such as vulnerability presence) without delivering a payload, making them a low-risk validation step before attempting exploitation. Exploit modules and payload generators actively attempt to compromise the host, and post-exploitation modules run only after successful access.
Why the other options are wrong
- B. Post-exploitation modules require prior successful compromise, which hasn't occurred yet.
- C. msfvenom generates payloads for exploitation, not vulnerability verification.
- D. Exploit modules attempt to actually compromise the host, which is riskier before validation.
Metasploit Module Types
Metasploit organizes functionality into module types, each serving a distinct role in the exploitation lifecycle.
- Auxiliary: scanning, fuzzing, DoS (no payload)
- Exploit: delivers payload to compromise a target
- Post: runs after successful exploitation for further actions
Memory trick: Auxiliary checks, Exploit strikes, Payload rides along, Post digs deeper