CEH Practice Question: Advanced Topics: Wireless, Cloud, IoT, Cryptography
Which tool is specifically designed to assess the security configuration of AWS, Azure, and GCP cloud environments by scanning for misconfigurations in services like S3, IAM, and EC2?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ScoutSuite
ScoutSuite is an open-source multi-cloud security auditing tool that checks for misconfigurations across AWS, Azure, and GCP. Pacu is an AWS exploitation framework; Aircrack-ng is for wireless; Reaver is for WPS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
ScoutSuite
Why this is correct
ScoutSuite is an open-source multi-cloud auditing tool specifically designed to assess the security posture of cloud environments. It enumerates resources and identifies potential misconfigurations, policy violations, and security weaknesses across major providers like Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP). This comprehensive scanning helps organizations proactively identify and remediate risks within their cloud infrastructure.
- ✗
Pacu
Why it's wrong here
Pacu is an open-source exploitation framework specifically tailored for penetration testing against Amazon Web Services (AWS) environments. Unlike a security posture assessment tool, Pacu focuses on post-exploitation activities, privilege escalation, and lateral movement within an already compromised AWS account, rather than scanning for initial misconfigurations across multiple cloud providers. Its purpose is offensive exploitation, not defensive configuration auditing.
- ✗
Reaver
Why it's wrong here
Reaver is a specialized tool primarily used for brute-forcing Wi-Fi Protected Setup (WPS) PINs to recover WPA/WPA2 passphrases on wireless networks. Its functionality is exclusively focused on exploiting vulnerabilities in the WPS protocol to gain unauthorized access to Wi-Fi networks. This makes Reaver entirely unrelated to assessing security configurations within cloud infrastructure environments.
- ✗
Aircrack-ng
Why it's wrong here
Aircrack-ng is a comprehensive suite of tools for auditing wireless networks, primarily focused on cracking WEP and WPA/WPA2-PSK keys. It includes utilities for packet capturing, injecting, and analyzing wireless traffic to compromise Wi-Fi network security. Its operational scope is limited to wireless local area networks, making it unsuitable for assessing the security posture of cloud-based infrastructure.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 870 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
3 more ways this is tested on CEH
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which of the following tools is specifically designed for assessing the security of AWS environments by checking for misconfigurations in services like S3, IAM, and EC2?
easy- ✓ A.ScoutSuite
- B.Aircrack-ng
- C.Nmap
- D.Wireshark
Why A: ScoutSuite is an open-source security auditing tool for cloud environments, including AWS. It checks for misconfigurations across multiple services and provides a detailed report.
Variation 2. Which cloud security assessment tool is specifically designed to audit AWS environments against best practices and CIS benchmarks?
medium- A.Pacu
- ✓ B.ScoutSuite
- C.Nessus
- D.Metasploit
Why B: ScoutSuite is an open-source tool that audits cloud environments (AWS, Azure, GCP) for security misconfigurations.
Variation 3. Which cloud security assessment tool is specifically designed to audit AWS environments for misconfigurations and provides a detailed report of findings?
easy- ✓ A.ScoutSuite
- B.Pacu
- C.Metasploit
- D.Nmap
Why A: ScoutSuite is an open-source tool that audits cloud environments (AWS, Azure, GCP) for security misconfigurations. It generates a comprehensive HTML report. Pacu is an exploitation framework, not an audit tool.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.