The word that does the work is authorised. A pen test begins with a written scope: what is in, what is off limits, what happens if something falls over, and who gets the call. Without that document the same activity is a crime, and the paperwork is not a formality — it is the thing that makes the exercise possible.
What distinguishes a test from a scan is that a human tries to chain things. A scanner reports that a version is outdated and that a form reflects input; a tester notices that one gives them a session and the other gives them somebody else's, and writes up the path between them with reproduction steps. The finding that matters is usually a combination, and combinations are what automation is worst at.
Expect a report you can act on: each finding with steps to reproduce it, an honest severity, and what it means in business terms. A four-hundred-item scanner export with the informational findings left in is not a penetration test.
Related terms
Red team
The offensive side: people whose job is to get in, using whatever an actual attacker would use.
Purple team
Running the attack and the defence as one exercise, so every fix is verified against the technique that found the hole.
Security audit
A systematic review of a system against a standard or a set of criteria, aiming for coverage rather than for a way in.
Threat model
A written answer to who would attack this, what they would want, and what would actually stop them.
The bench this belongs to
CybersecurityPurple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.
