ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 407 - PT0-002 discussion

Report
Export

During an assessment, a penetration tester needs to perform a cloud asset discovery of an organization. Which of the following tools would most likely provide more accurate results in this situation?

A.
Pacu
Answers
A.
Pacu
B.
Scout Suite
Answers
B.
Scout Suite
C.
Shodan
Answers
C.
Shodan
D.
TruffleHog
Answers
D.
TruffleHog
Suggested answer: B

Explanation:

Scout Suite is an open-source multi-cloud security-auditing tool that enables security posture assessment of cloud environments. It is designed to provide a comprehensive and accurate analysis of cloud assets by using the APIs of cloud service providers. Scout Suite supports major cloud platforms, including AWS, Azure, and GCP, making it suitable for performing cloud asset discovery.

Other tools listed, such as Pacu, Shodan, and TruffleHog, serve different purposes. Pacu is a cloud exploitation framework for AWS, Shodan is a search engine for internet-connected devices, and TruffleHog is a tool for searching for secrets in files. While they are valuable tools, Scout Suite is specifically tailored for comprehensive cloud asset discovery.

Scout Suite GitHub page: Scout Suite

Cloud security auditing examples from penetration testing reports and best practices.

asked 02/10/2024
Danilo Ferrareis
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first