Courseiva
Advanced Topics: Wireless, Cloud, IoT, CryptographymediumMultiple SelectObjective-mapped

CEH Practice Question: Advanced Topics: Wireless, Cloud, IoT, Cryptography

Which TWO tools are specifically designed for cloud security auditing and exploitation? (Choose two.)

⚠ Common exam trap

EC-Council often tests the distinction between general-purpose security tools (Nessus, Nmap) and cloud-specific frameworks (ScoutSuite, Pacu), expecting candidates to recognize that tools like Aircrack-ng are strictly for wireless, not cloud, environments.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

ScoutSuite

ScoutSuite is an open-source multi-cloud security-auditing tool that assesses the security posture of AWS, Azure, and GCP environments by checking for misconfigurations, excessive permissions, and compliance violations. Pacu is an AWS exploitation framework designed for offensive security testing, allowing penetration testers to enumerate resources, escalate privileges, and execute post-exploitation modules against cloud accounts. Both tools are purpose-built for cloud security auditing and exploitation, making them the correct choices.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ScoutSuite

    Why this is correct

    ScoutSuite is a comprehensive open-source multi-cloud security auditing tool designed to identify misconfigurations and potential vulnerabilities across various cloud providers, including AWS, Azure, GCP, Alibaba Cloud, and OCI. It maps out the attack surface of cloud environments by fetching configuration data via API calls and presenting it in an intuitive, interactive HTML report. This allows security professionals to quickly assess the security posture and compliance of their cloud infrastructure.

  • Nessus

    Why it's wrong here

    Nessus is a widely recognized commercial vulnerability scanner primarily focused on identifying security weaknesses in network devices, operating systems, applications, and databases. While it can scan virtual machines or instances deployed within a cloud environment, its core functionality does not extend to auditing cloud provider-specific services, configurations, or API-level security controls. It operates at the network and host level, making it a general-purpose tool rather than one specifically designed for cloud native security posture management.

  • Aircrack-ng

    Why it's wrong here

    Aircrack-ng is a specialized suite of tools dedicated exclusively to wireless network security assessment and exploitation, specifically targeting 802.11 Wi-Fi standards. Its functionalities include packet capturing, WEP/WPA/WPA2 key cracking, and injecting frames to test the robustness of wireless access points and client devices. This toolset is entirely focused on the physical and data link layers of wireless communication, bearing no direct relevance to cloud infrastructure or service security.

  • Nmap

    Why it's wrong here

    Nmap, or Network Mapper, is a powerful open-source utility for network discovery and security auditing, capable of identifying hosts, services, operating systems, and open ports on a network. While it can be used to scan the public IP addresses of cloud-hosted instances, it does not interact with cloud provider APIs or analyze cloud-native services like S3 buckets, IAM roles, or serverless functions. Its design is fundamentally centered on traditional IP-based network scanning, not cloud platform-specific security assessments.

  • Pacu

    Why this is correct

    Pacu is an open-source exploitation framework meticulously crafted for penetration testing and red teaming within Amazon Web Services (AWS) environments. It provides a modular approach with numerous modules designed to exploit common AWS misconfigurations, escalate privileges, and perform various attack scenarios by leveraging AWS API calls. This tool is specifically engineered to interact with and compromise AWS services, making it a dedicated cloud security exploitation utility.

About these practice questions

One of 870 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.