Courseiva

CEH Practice Question: Advanced Topics: Wireless, Cloud, IoT, Cryptography

Which tool is specifically designed to assess the security configuration of AWS, Azure, and GCP cloud environments by scanning for misconfigurations in services like S3, IAM, and EC2?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

ScoutSuite

ScoutSuite is an open-source multi-cloud security auditing tool that checks for misconfigurations across AWS, Azure, and GCP. Pacu is an AWS exploitation framework; Aircrack-ng is for wireless; Reaver is for WPS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ScoutSuite

    Why this is correct

    ScoutSuite is an open-source multi-cloud auditing tool specifically designed to assess the security posture of cloud environments. It enumerates resources and identifies potential misconfigurations, policy violations, and security weaknesses across major providers like Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP). This comprehensive scanning helps organizations proactively identify and remediate risks within their cloud infrastructure.

  • Pacu

    Why it's wrong here

    Pacu is an open-source exploitation framework specifically tailored for penetration testing against Amazon Web Services (AWS) environments. Unlike a security posture assessment tool, Pacu focuses on post-exploitation activities, privilege escalation, and lateral movement within an already compromised AWS account, rather than scanning for initial misconfigurations across multiple cloud providers. Its purpose is offensive exploitation, not defensive configuration auditing.

  • Reaver

    Why it's wrong here

    Reaver is a specialized tool primarily used for brute-forcing Wi-Fi Protected Setup (WPS) PINs to recover WPA/WPA2 passphrases on wireless networks. Its functionality is exclusively focused on exploiting vulnerabilities in the WPS protocol to gain unauthorized access to Wi-Fi networks. This makes Reaver entirely unrelated to assessing security configurations within cloud infrastructure environments.

  • Aircrack-ng

    Why it's wrong here

    Aircrack-ng is a comprehensive suite of tools for auditing wireless networks, primarily focused on cracking WEP and WPA/WPA2-PSK keys. It includes utilities for packet capturing, injecting, and analyzing wireless traffic to compromise Wi-Fi network security. Its operational scope is limited to wireless local area networks, making it unsuitable for assessing the security posture of cloud-based infrastructure.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 870 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on CEH

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which of the following tools is specifically designed for assessing the security of AWS environments by checking for misconfigurations in services like S3, IAM, and EC2?

easy
  • A.ScoutSuite
  • B.Aircrack-ng
  • C.Nmap
  • D.Wireshark

Why A: ScoutSuite is an open-source security auditing tool for cloud environments, including AWS. It checks for misconfigurations across multiple services and provides a detailed report.

Variation 2. Which cloud security assessment tool is specifically designed to audit AWS environments against best practices and CIS benchmarks?

medium
  • A.Pacu
  • B.ScoutSuite
  • C.Nessus
  • D.Metasploit

Why B: ScoutSuite is an open-source tool that audits cloud environments (AWS, Azure, GCP) for security misconfigurations.

Variation 3. Which cloud security assessment tool is specifically designed to audit AWS environments for misconfigurations and provides a detailed report of findings?

easy
  • A.ScoutSuite
  • B.Pacu
  • C.Metasploit
  • D.Nmap

Why A: ScoutSuite is an open-source tool that audits cloud environments (AWS, Azure, GCP) for security misconfigurations. It generates a comprehensive HTML report. Pacu is an exploitation framework, not an audit tool.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.