| Vulnerability Assessment (VA) | Penetration Testing (PT) |
| Identifies the vulnerabilities in a network | Identifies vulnerabilities to exploit them to penetrate the system |
| Tells how susceptible the network is | Tells whether the detected vulnerability is genuine |
| Conducted at regular intervals when there is a change in the system or network | Conducted annually when there are significant changes introduced into the system |