I would like to DIFFERENTIATE them as

1. VA (Vulnerability Assessment) as a step-by-step process like

  • Define Assets
  • Scan assets for vulnerabilities
  • Prioritize the assets according to their Importance and Vulnerabilities in them
  • Generate Report
2. PT (Penetration testing) as a random process which includes
  • Take any asset
  • Pen-test (Ethical Hack) asset
  • Generate report with all the vulnerabilities

