CEH Practice Question: Advanced Topics: Wireless, Cloud, IoT, Cryptography
Which TWO of the following tools are used for cloud security auditing or exploitation?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ScoutSuite
ScoutSuite (A) is a multi-cloud security auditing tool that queries cloud provider APIs (AWS, Azure, GCP, etc.) to enumerate resources and flag misconfigurations, making it a cloud security auditing tool. Pacu (C) is an open-source AWS exploitation framework designed for offensive security testing of cloud environments, providing modules for enumeration, privilege escalation, and persistence, so it fits cloud exploitation. John the Ripper (B) is an offline password cracker, Nessus (D) is a general-purpose vulnerability scanner for hosts and networks, and Aircrack-ng (E) is a Wi-Fi (802.11) wireless security auditing suite — none of these are specifically cloud security auditing or exploitation tools.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
ScoutSuite
Why this is correct
ScoutSuite is a multi-cloud auditing tool that queries provider APIs to enumerate configuration weaknesses across AWS, Azure, GCP and others. It satisfies the stem's auditing criterion by producing a security posture report without exploiting the environment.
- ✗
John the Ripper
Why it's wrong here
John the Ripper cracks password hashes offline, targeting local credential files rather than cloud APIs, configurations or hosted services. It is tempting because weak cloud credentials are a real exposure, but it is the correct choice for offline hash auditing, not for assessing cloud infrastructure posture or exploiting cloud-specific misconfigurations.
- ✓
Pacu
Why this is correct
Pacu is an AWS exploitation framework, providing modules for enumerating IAM permissions, privilege escalation and lateral movement within cloud accounts. It satisfies the auditing-or-exploitation criterion by actively probing misconfigured AWS environments, unlike passive assessment tools. This makes it a valid selection alongside ScoutSuite for the cloud security auditing question.
- ✗
Nessus
Why it's wrong here
Nessus is a vulnerability scanner for hosts and networks, not a cloud-specific auditing or exploitation tool, so it does not assess cloud configuration posture or IAM. It is tempting because it is a well-known security assessment tool, and it would be correct for on-premises vulnerability scanning engagements.
- ✗
Aircrack-ng
Why it's wrong here
Aircrack-ng attacks Wi-Fi encryption and captures wireless frames, operating at layer 2 against 802.11 networks, not cloud APIs or hosted configurations. It is tempting because wireless and cloud both fall under perimeter concerns, but it is the correct choice for WLAN auditing, not cloud security assessment.
Go deeper
Related to this question
Learn chapter
Penetration Testing and Reporting
Key term
Password Cracking
Password cracking is the process of using software tools or techniques to recover unknown passwords from stored data or by guessing them systematically.
Key term
Privilege escalation
Privilege escalation is when a user or attacker gains more access or control over a system than they are supposed to have.
About these practice questions
This CEH question is part of Courseiva's 913-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.