CEH Practice Question: Advanced Topics: Wireless, Cloud, IoT, Cryptography
A penetration tester uses the tool 'Pacu' during an AWS security assessment. Which phase of testing is Pacu most commonly associated with?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Exploitation and post-exploitation
Pacu is an exploitation framework for AWS, used after initial access to escalate privileges, pivot, and maintain access. It is not typically used for initial reconnaissance (Nmap, ScoutSuite) or reporting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reporting and documentation
Why it's wrong here
Pacu is an active exploitation framework designed for interactive penetration testing within AWS environments. Its primary function involves executing modules to identify and exploit misconfigurations or vulnerabilities, not to compile or format the findings into formal reports. While a penetration tester would document their actions and findings, Pacu itself does not possess features for generating comprehensive reports, executive summaries, or compliance-focused documentation, which are distinct post-engagement activities.
- ✗
Vulnerability scanning
Why it's wrong here
Vulnerability scanning primarily involves identifying potential security weaknesses and misconfigurations within a target environment, often through passive enumeration or non-intrusive checks against known vulnerability databases. Tools for this purpose typically generate lists of findings without attempting to compromise the system. In contrast, Pacu is an active exploitation framework that directly interacts with AWS APIs to test and exploit identified misconfigurations, perform privilege escalation, or establish persistence, moving far beyond mere vulnerability identification.
- ✓
Exploitation and post-exploitation
Why this is correct
Pacu is specifically engineered as an open-source exploitation framework for AWS, providing a comprehensive suite of modules tailored for active penetration testing. It excels in the exploitation phase by leveraging identified misconfigurations or weak credentials to gain unauthorized access or elevate privileges within an AWS account. Furthermore, Pacu facilitates post-exploitation activities such as establishing persistence, enumerating sensitive data, performing lateral movement across AWS services, and backdooring resources, making it a powerful tool for simulating real-world attacks.
- ✗
Reconnaissance
Why it's wrong here
Reconnaissance, in the context of penetration testing, involves the initial phase of gathering information about a target environment to understand its structure, services, and potential attack surface. Tools like ScoutSuite or Nmap are designed for passive or semi-passive enumeration of resources and configurations. While Pacu might perform some initial enumeration as part of its module execution, its core design and extensive module set are geared towards actively exploiting identified weaknesses and performing post-exploitation actions, rather than comprehensive, initial information gathering.
Go deeper
Related to this question
About these practice questions
One of 870 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.