CompTIA PenTest+ (PT0-003)Vulnerability Discovery and AnalysisHard
A pentester is contracted to assess a client's security posture across AWS, Azure, and GCP environments simultaneously, focusing on identifying misconfigured storage permissions, overly permissive IAM roles, and insecure default settings across all three providers. Which tool is best suited for this multi-cloud configuration assessment?
- ANikto
- BKismet
- CShodan
- DScoutSuite
Show answer & explanationAnswer & explanation
Correct answer: D. ScoutSuite
ScoutSuite is an open-source, multi-cloud security auditing tool that assesses configurations across AWS, Azure, and GCP for issues like misconfigured storage, excessive IAM permissions, and insecure defaults, producing a consolidated report. Shodan is an internet-connected device search engine, Nikto scans web servers for vulnerabilities, and Kismet is a wireless network detection tool—none of which perform cross-cloud configuration auditing.
Why the other options are wrong
- A. Nikto scans web servers for outdated software and known flaws, not cloud configurations.
- B. Kismet is a wireless discovery and monitoring tool, unrelated to cloud environments.
- C. Shodan indexes internet-exposed devices/services; it does not audit cloud IAM configurations.
ScoutSuite (Cloud Security Auditing)
An open-source, multi-cloud security auditing tool that assesses AWS, Azure, and GCP configurations to identify misconfigurations such as overly permissive IAM policies and exposed storage.
- Supports AWS, Azure, GCP, and other providers
- Generates HTML reports highlighting risky configurations
- Used for cloud security posture management (CSPM) style assessments
Memory trick: ScoutSuite 'scouts' every cloud provider's misconfigurations at once