Prowler is designed for cloud security assessment, configuration review, and compliance evaluation, which directly meets the requirement to establish cloud-security baselines. The project's official repository describes Prowler as an open-source cloud security platform that automates security and compliance assessments across cloud environments and provides extensive security checks, reporting, and remediation guidance.
Baseline assessments establish an expected security posture against which subsequent configurations and changes can be evaluated. Prowler can examine cloud settings such as identity permissions, logging, encryption, public exposure, network controls, storage configuration, and service-specific security features. This allows the vulnerability-management team to identify deviations from security and compliance expectations.
Metasploit is an exploitation framework used primarily for penetration testing and validation of exploitable weaknesses. Maltego is an information-gathering and relationship-mapping platform frequently associated with OSINT and infrastructure reconnaissance. MITRE CALDERA is an adversary-emulation platform used to exercise defensive controls using automated attack techniques.
The term “cloud environment” combined with “security baselines” points directly toward a cloud posture and compliance assessment tool rather than exploitation, OSINT, or adversary simulation.
Study Guide Reference: Vulnerability Management → Cloud Assessments → Prowler → Security Baselines → Configuration Auditing → Compliance Checks → Cloud Security Posture.