CompTIA PenTest+ (PT0-003)Vulnerability Discovery and AnalysisMedium

A pentester is performing cloud discovery against a client's AWS environment as part of the reconnaissance phase. The client is concerned about publicly exposed object storage containing sensitive data. Which approach would MOST effectively identify misconfigured or publicly accessible storage buckets?

  1. ALaunching a Burp Suite active scan against the AWS Management Console login page
  2. BRunning hashcat against exported IAM access keys
  3. CRunning an Nmap version scan against known AWS IP ranges
  4. DUsing a purpose-built enumeration tool such as S3Scanner to identify bucket names and permissions
Show answer & explanation

Correct answer: D. Using a purpose-built enumeration tool such as S3Scanner to identify bucket names and permissions

Tools like S3Scanner are designed specifically to enumerate S3 bucket names (via naming conventions, DNS, or brute force) and check their permissions/ACLs for public exposure. Nmap version scanning, hashcat, and Burp active scanning are not suited to identifying misconfigured object storage.

Why the other options are wrong

  • A. Burp's active scanner tests web app vulnerabilities, not bucket-level ACL misconfigurations.
  • B. Hashcat cracks password hashes, unrelated to storage bucket enumeration.
  • C. Nmap targets network services/ports, not object storage bucket permissions.

Cloud Storage Enumeration

The process of discovering and assessing cloud object storage (e.g., AWS S3, Azure Blob) for public exposure or misconfigured access controls.

  • Tools: S3Scanner, Bucket Finder, ScoutSuite, CloudBrute
  • Checks bucket naming, DNS entries, and ACL/policy settings
  • Common finding: publicly readable/writable buckets exposing sensitive data

Memory trick: Cloud Recon: DNS, Storage buckets, IAM policies, Metadata, Subdomains

More Vulnerability Discovery and Analysis questions