Penetration test
Also known as Pentest, Pen test
An authorized simulated attack against your systems to find and demonstrate exploitable weaknesses before a real attacker does.
A tester works the way an attacker would: mapping what is exposed, finding weaknesses, chaining them together, and proving impact. The deliverable is evidence of what could actually be done, not a list of theoretical issues.
It differs from a vulnerability scan in that a human is doing the thinking. Scanners find known issues in isolation; a tester combines a weak password, an over-permissioned share, and an unpatched service into a path to your data.
Where this comes up
Penetration test sits inside our penetration testing work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.