Penetration Test vs. Vulnerability Scan
Both look for security weaknesses, but a vulnerability scan is mostly automated, with a tool like Nessus or Qualys listing known issues. A penetration test is a person actively trying to break in, chaining weaknesses together the way a real attacker would. Someone who has run scans hasn't necessarily done a pentest.
How to tell them apart on a resume
Vulnerability Scanning
Nessus, Qualys, Rapid7, scan schedules, CVSS scores, patch tracking, remediation reports.
Penetration Testing
Burp Suite, Metasploit, OSCP or similar certifications, exploited findings, written attack narratives, scoped engagements.
The question that settles it
“Did you run tools that listed vulnerabilities, or did you personally exploit them to show how far an attacker could get?”
Read the full definitions
Open the full tool for the other look-alike pairs, role profiles, and the JD decoder.