Courseiva

CEH Practice Question: Advanced Topics: Wireless, Cloud, IoT, Cryptography

Which TWO of the following tools are used for cloud security auditing or exploitation?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ScoutSuite

ScoutSuite (A) is a multi-cloud security auditing tool that queries cloud provider APIs (AWS, Azure, GCP, etc.) to enumerate resources and flag misconfigurations, making it a cloud security auditing tool. Pacu (C) is an open-source AWS exploitation framework designed for offensive security testing of cloud environments, providing modules for enumeration, privilege escalation, and persistence, so it fits cloud exploitation. John the Ripper (B) is an offline password cracker, Nessus (D) is a general-purpose vulnerability scanner for hosts and networks, and Aircrack-ng (E) is a Wi-Fi (802.11) wireless security auditing suite — none of these are specifically cloud security auditing or exploitation tools.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    ScoutSuite

    Why this is correct

    ScoutSuite is a multi-cloud auditing tool that queries provider APIs to enumerate configuration weaknesses across AWS, Azure, GCP and others. It satisfies the stem's auditing criterion by producing a security posture report without exploiting the environment.

  • ✗

    John the Ripper

    Why it's wrong here

    John the Ripper cracks password hashes offline, targeting local credential files rather than cloud APIs, configurations or hosted services. It is tempting because weak cloud credentials are a real exposure, but it is the correct choice for offline hash auditing, not for assessing cloud infrastructure posture or exploiting cloud-specific misconfigurations.

  • ✓

    Pacu

    Why this is correct

    Pacu is an AWS exploitation framework, providing modules for enumerating IAM permissions, privilege escalation and lateral movement within cloud accounts. It satisfies the auditing-or-exploitation criterion by actively probing misconfigured AWS environments, unlike passive assessment tools. This makes it a valid selection alongside ScoutSuite for the cloud security auditing question.

  • ✗

    Nessus

    Why it's wrong here

    Nessus is a vulnerability scanner for hosts and networks, not a cloud-specific auditing or exploitation tool, so it does not assess cloud configuration posture or IAM. It is tempting because it is a well-known security assessment tool, and it would be correct for on-premises vulnerability scanning engagements.

  • ✗

    Aircrack-ng

    Why it's wrong here

    Aircrack-ng attacks Wi-Fi encryption and captures wireless frames, operating at layer 2 against 802.11 networks, not cloud APIs or hosted configurations. It is tempting because wireless and cloud both fall under perimeter concerns, but it is the correct choice for WLAN auditing, not cloud security assessment.

About these practice questions

This CEH question is part of Courseiva's 913-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.