An audit and a penetration test answer different questions and are routinely confused. The audit asks whether the controls that should exist do exist, across the whole surface, including the parts an attacker would never bother with. The test asks whether somebody can get in, and stops when they do.
Which one you want depends on the question you are actually asking. "Can we be broken into" is a test. "Are we sound, and can we show somebody that we are" is an audit. Compliance and due diligence generally want the second, and the two are complementary rather than substitutes — an audit with no testing behind it is a review of intentions.
Related terms
Penetration test
An authorised, scoped attempt to break into a system, done to find out what an attacker could actually achieve.
OWASP Top 10
The long-standing community list of the most critical web application security risks, revised every few years.
Threat model
A written answer to who would attack this, what they would want, and what would actually stop them.
Purple team
Running the attack and the defence as one exercise, so every fix is verified against the technique that found the hole.
The bench this belongs to
CybersecurityPurple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.
