CEH Practice Question: Advanced Topics: Wireless, Cloud, IoT, Cryptography
Which cloud security assessment tool is specifically designed to audit AWS environments against best practices and CIS benchmarks?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ScoutSuite
ScoutSuite is an open-source tool that audits cloud environments (AWS, Azure, GCP) for security misconfigurations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Pacu
Why it's wrong here
Pacu is an open-source exploitation framework specifically tailored for penetration testing AWS environments, focusing on post-exploitation and privilege escalation techniques. Unlike auditing tools, Pacu provides a collection of modules designed to exploit identified misconfigurations or vulnerabilities to gain further access, exfiltrate data, or escalate privileges within an already compromised AWS account. It serves as an offensive tool for simulating real-world attacks, rather than a defensive tool for proactive security posture assessment.
- ✓
ScoutSuite
Why this is correct
ScoutSuite is an open-source multi-cloud security auditing tool specifically engineered to assess the security posture of cloud environments across major providers like AWS, Azure, GCP, Alibaba Cloud, and OCI. It achieves this by leveraging cloud provider APIs to collect configuration data and then identifies security 'findings' or misconfigurations against a comprehensive set of predefined best practices and compliance rules. The tool generates an interactive HTML report, highlighting potential attack surfaces and compliance deviations within the cloud infrastructure.
- ✗
Nessus
Why it's wrong here
Nessus is a widely recognized vulnerability scanner primarily designed for identifying security weaknesses in traditional IT infrastructure, including operating systems, network devices, and web applications. While it can scan virtual machines hosted in the cloud, it lacks the native integration with cloud provider APIs necessary to audit cloud-specific services, configurations, and Identity and Access Management (IAM) policies effectively. Therefore, it is not specifically designed for comprehensive cloud security posture management.
- ✗
Metasploit
Why it's wrong here
Metasploit is a powerful open-source penetration testing framework used for developing, testing, and executing exploit code against remote target systems. Its primary function is to facilitate post-exploitation activities, such as gaining shell access, escalating privileges, and pivoting within a compromised network, rather than performing initial security assessments or audits of cloud configurations. It is an exploitation tool, not an assessment tool for identifying cloud misconfigurations.
Go deeper
Related to this question
About these practice questions
This CEH question is part of Courseiva's 870-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.