CEH Practice Question: Advanced Topics: Wireless, Cloud, IoT, Cryptography
A penetration tester uses the tool 'Pacu' during an assessment. Which of the following actions is Pacu designed to perform?
⚠ Common exam trap
CEH often tests the specific cloud platform a tool targets: candidates may confuse Pacu with Azure tools or general-purpose scanners, but Pacu is exclusively for AWS exploitation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automate penetration testing tasks in AWS environments
Pacu is an open-source AWS exploitation framework designed to automate penetration testing tasks in AWS environments. It provides a modular structure with modules for enumeration, privilege escalation, persistence, and data exfiltration, specifically targeting AWS services like IAM, S3, EC2, and Lambda. It is not used for Azure, network scanning, or wireless attacks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Exploit vulnerabilities in Azure cloud infrastructure
Why it's wrong here
Pacu is an open-source exploitation framework designed exclusively for Amazon Web Services (AWS) environments. Its modules are tailored to interact with AWS APIs and services, identifying and exploiting misconfigurations or vulnerabilities within AWS accounts. Therefore, it lacks the necessary functionalities and specific attack modules to target or exploit vulnerabilities within Microsoft Azure's distinct cloud infrastructure and service offerings.
- ✓
Automate penetration testing tasks in AWS environments
Why this is correct
Pacu is an advanced open-source exploitation framework specifically engineered to automate various penetration testing tasks within Amazon Web Services (AWS) environments. It provides a modular approach, allowing testers to enumerate resources, identify misconfigurations, and execute post-exploitation activities against AWS services like EC2, S3, IAM, and Lambda. This automation significantly streamlines the process of discovering and exploiting security weaknesses in complex AWS deployments.
- ✗
Perform network scanning and service enumeration
Why it's wrong here
Pacu is not designed for traditional network scanning or service enumeration, which typically involves direct interaction with IP addresses and ports using tools like Nmap. Instead, Pacu operates at the API level within AWS, leveraging credentials to query and interact with cloud services. Its focus is on identifying misconfigurations and vulnerabilities within the AWS ecosystem itself, rather than discovering open ports or services on arbitrary network hosts.
- ✗
Crack WPA2 handshakes using dictionary attacks
Why it's wrong here
Cracking WPA2 handshakes involves capturing wireless network traffic and performing offline dictionary or brute-force attacks against the captured four-way handshake, typically using specialized tools such as Aircrack-ng or Hashcat. Pacu, conversely, is an AWS-specific exploitation framework that operates within cloud environments and has no capabilities or modules related to wireless network security or cryptographic attacks against Wi-Fi protocols.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
Learn chapter
Penetration Testing and Reporting
Key term
Nmap Scanning
Nmap scanning is a method used to discover devices running on a network and find open ports, services, and security weaknesses.
Key term
Privilege escalation
Privilege escalation is when a user or attacker gains more access or control over a system than they are supposed to have.
About these practice questions
One of 913 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official EC-Council exam blueprint
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.