What is the difference between a vulnerability scan and a pentest?
A scan walks what is exposed and returns a list: CVE, a weak setting, an old version. It does not prove someone gets in. A pentest takes those candidates — and what the scanner missed — and tries to exploit. If it opens, the report has the path, the impact and what to close. If it does not, the alert is not a cover finding. Buying only a scan and calling it a pentest buys volume. A team that needs to decide a sprint needs the path.