Security testing
A vulnerability scan, a penetration test, a red team exercise and a bug bounty answer different questions, and they get bought interchangeably.
A scan finds known flaws at scale. A penetration test has a person actively looking, within a scope and a time box. A red team asks whether you would notice and respond to a determined attacker. A bug bounty is many people looking, continuously, for whatever they can find. Buying one and expecting the answer to another is a common and expensive mistake.
Checked against the primary source.
