{"id":99021,"date":"2026-09-03T09:00:00","date_gmt":"2026-09-03T07:00:00","guid":{"rendered":"http:\/\/locaterisk.com\/de\/?post_type=wissen&#038;p=99021"},"modified":"2026-08-06T16:22:12","modified_gmt":"2026-08-06T14:22:12","slug":"vulnerability-scan-penetration-test-security-audit-easm","status":"publish","type":"wissen","link":"https:\/\/locaterisk.com\/en\/know\/vulnerability-scan-penetration-test-security-audit-easm\/","title":{"rendered":"Vulnerability Scan, Penetration Test, Security Audit, or EASM: Which Approach Is Right for You?"},"content":{"rendered":"<h1 class=\"wp-block-heading\">Vulnerability Scan, Penetration Test, Security Audit, or EASM: Which Approach Is Right for You?<\/h1>\n\n<span class=\"lr-ai-disclosure\" style=\"display:block;max-width:843px;margin:8px auto 28px;font-size:14px;line-height:1.4;color:#8b93a7;font-family:inherit;font-style:italic;\">This text was generated using artificial intelligence (AI).<\/span>\n\n<h2 class=\"wp-block-heading\">Key Points at a Glance<\/h2>\n<ul class=\"wp-block-list\"><li>A vulnerability scan automatically searches for known vulnerabilities and suspicious configurations within a defined technical scope.<\/li><li>A penetration test, conducted with clear authorization and an agreed-upon scope, verifies whether and how selected vulnerabilities can be exploited or combined in practice.<\/li><li>A security audit evaluates documentation, processes, and controls against established criteria; technical tests may be part of the audit.<\/li><li>EASM regularly monitors the external attack surface from an outside-in perspective and supports discovery and prioritization.<\/li><li>These methods address different questions. Combining them is often a good idea when the scope and handoffs are determined in advance.<\/li><\/ul>\n<h2 class=\"wp-block-heading\">The key question comes before the method<\/h2>\n<p class=\"wp-block-paragraph\">The choice between a vulnerability scan, penetration test, security audit, and external attack surface management doesn\u2019t start with a product name. It starts with the question you need to answer. Are you looking for known technical vulnerabilities in a defined environment? Do you want to test the practical exploitability of a critical system? Do you need evidence to demonstrate the implementation of defined controls? Or do you lack an up-to-date view of publicly accessible assets?<\/p>\n<p class=\"wp-block-paragraph\">NIST SP 800-115 classifies technical tests and assessments by purpose, planning, execution, and evaluation. The guide emphasizes the benefits and limitations of individual techniques. The BSI also distinguishes between different levels of testing and points out that active methods can impact systems. This leads to a key procurement rule: the level of testing and authorization must be commensurate with information needs and operational risk.<\/p>\n<p class=\"wp-block-paragraph\">The four methods do not fall on a simple scale from weak to strong. An audit addresses a different question than a penetration test. EASM has a different timeframe than a one-time scan. An automated scan can regularly check a broad, known set of assets, while a manual test examines selected attack vectors in greater depth.<\/p>\n<p class=\"wp-block-paragraph\">Therefore, before making a selection, define the scope, assets to be protected, expected decision, permissible interventions, and desired output format. The following matrix is intended to help with classification and does not replace a project-specific statement of work.<\/p>\n<figure class=\"wp-block-table\"><table><thead><tr><th>Criterion<\/th><th>Vulnerability Scan<\/th><th>Penetration Test<\/th><th>Security Audit<\/th><th>EASM<\/th><\/tr><\/thead><tbody><tr><td>Key Question<\/td><td>What known technical weaknesses or configuration issues are detected by Scope?<\/td><td>Can selected weaknesses be put to practical use or combined under agreed-upon conditions?<\/td><td>Have the defined requirements and controls been implemented in a transparent manner?<\/td><td>Which externally visible assets and exposures are changing?<\/td><\/tr><tr><td>Typical Scope<\/td><td>Known hosts, applications, or networks<\/td><td>Well-defined systems, applications, or scenarios<\/td><td>Organization, process, control area, or system<\/td><td>Internet-exposed infrastructure around well-known entry points<\/td><\/tr><tr><td>Depth<\/td><td>Mostly automated; authenticated or handled externally, depending on the process<\/td><td>Targeted manual and technical testing with an agreed-upon scope of testing<\/td><td>Document review, interviews, spot checks, and, if necessary, technical inspections<\/td><td>Recurring Outside-In Discovery and Observation<\/td><\/tr><tr><td>Authorization<\/td><td>Test order and technical approval required<\/td><td>Detailed rules, approvals, limits, and emergency contacts are required<\/td><td>Audit Scope, Criteria, Access to Evidence, and Points of Contact<\/td><td>Clear organizational structure and permissible non-invasive testing<\/td><\/tr><tr><td>Date and Time<\/td><td>Regularly and after changes<\/td><td>Before releases, after major changes, or on a risk-based basis<\/td><td>Based on an audit program, regulatory requirements, or contractual obligations<\/td><td>Continuous or recurring<\/td><\/tr><tr><td>Output<\/td><td>List of Technical Findings with Evidence and Priority<\/td><td>Validated Attack Vectors, Impacts, and Recommendations<\/td><td>Deviations, Supporting Documentation, and Evaluation Against Criteria<\/td><td>Asset inventory, external findings, trends, and prioritization indicators<\/td><\/tr><\/tbody><\/table><\/figure>\n<h2 class=\"wp-block-heading\">Vulnerability Scan: Repeatedly Test Known Systems<\/h2>\n<p class=\"wp-block-paragraph\">A vulnerability scan examines a defined technical infrastructure for known vulnerabilities, missing security updates, or suspicious configurations. Depending on the tool and the task, it operates from the outside, using credentials, or via installed components. Authenticated scans can incorporate internal version and configuration information. External scans primarily examine the accessible surface.<\/p>\n<p class=\"wp-block-paragraph\">This method is suitable for regular audits of known assets, for patch and configuration processes, and as preparation for more in-depth testing. Automation ensures repeatable rules and broad coverage within the defined scope. At the same time, it generates a need for testing. Version characteristics can be misinterpreted, compensating controls may remain unnoticed, and some application logic cannot be evaluated automatically.<\/p>\n<p class=\"wp-block-paragraph\">In its guidelines on penetration testing, the BSI highlights the issue of false positives in automated methods and the potential disruptions caused by more invasive tests. Therefore, the scope of work should specify whether issues are to be merely identified, actively confirmed, or investigated further. Production systems require appropriate time windows, termination criteria, and designated contacts.<\/p>\n<p class=\"wp-block-paragraph\">A good scan report distinguishes between observation and assessment. It specifies the asset, the time, the testing method, the evidence, the uncertainty, and the recommended validation. The number of findings alone does not determine risk priority; business criticality, accessibility, and actual impact must also be considered.<\/p>\n<h2 class=\"wp-block-heading\">Penetration Test: Validating Selected Attack Vectors<\/h2>\n<p class=\"wp-block-paragraph\">NIST describes penetration testing as a security test in which testers simulate real-world attacks to identify ways to bypass security measures. Often, multiple vulnerabilities are combined. This level of depth can reveal whether an assumption holds true in practice and what impact can be achieved within the agreed-upon limits.<\/p>\n<p class=\"wp-block-paragraph\">A penetration test is appropriate for critical applications, significant architectural changes, new external interfaces, and specific risk scenarios. For web applications, the OWASP Web Security Testing Guide provides a structured framework. The test should be based on an up-to-date description of the architecture and scope. Otherwise, the team may invest a great deal of effort in a low-priority target.<\/p>\n<p class=\"wp-block-paragraph\">Authorization is key. Rules of engagement specify the systems, permitted techniques, time frame, test accounts, data handling, emergency contacts, termination rules, and reporting procedures. Shared cloud or provider infrastructure may require additional approvals. The test may only take place within the scope of this agreement.<\/p>\n<p class=\"wp-block-paragraph\">A penetration test provides a snapshot of the tested scope and the method used as of a specific date. The absence of a successful attack does not prove that no vulnerabilities exist. New releases and configurations can alter the results. After vulnerabilities have been addressed, a targeted follow-up test is recommended.<\/p>\n<h2 class=\"wp-block-heading\">Security Audit: Review Controls and Evidence Against Criteria<\/h2>\n<p class=\"wp-block-paragraph\">A security audit examines whether defined requirements and controls have been implemented in a verifiable manner. The criteria may be derived from internal policies, contracts, standards, or regulatory requirements. Auditors review documents, roles, process documentation, configurations, and random samples. Technical tests can provide evidence, but they are not automatically the sole focus.<\/p>\n<p class=\"wp-block-paragraph\">This audit is appropriate when an organization wishes to assess its governance, responsibilities, and the effectiveness of its controls. Examples include authorization processes, vulnerability management, supplier management, and emergency preparedness. The validity of the results depends on the criteria, scope, audit period, and the quality of the samples.<\/p>\n<p class=\"wp-block-paragraph\">An audit report should clearly link requirements, audited evidence, nonconformities, and assessments. It may include recommendations or corrective actions. An audit does not replace an in-depth technical review when the key question is whether a specific application can be exploited. Conversely, a penetration test does not automatically determine whether an organization-wide process is being effectively managed.<\/p>\n<p class=\"wp-block-paragraph\">When procuring these services, it must be clear whether an internal review, an independent audit, or a formal certification audit is required. These services differ in terms of qualifications, independence, reporting, and potential recognition. The term \u201esecurity audit\u201c alone does not specify this.<\/p>\n<h2 class=\"wp-block-heading\">EASM: Monitor Unknown External Assets and Changes<\/h2>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/locaterisk.com\/en\/know\/what-is-easm\/\">External Attack Surface Management<\/a> examines the internet-facing attack surface from an outside-in perspective. Microsoft describes EASM as the continuous discovery and mapping of external infrastructure. Known domains, hosts, IP ranges, or organizational information can serve as starting points for identifying additional candidates.<\/p>\n<p class=\"wp-block-paragraph\">EASM is appropriate when the known inventory does not reliably reflect external reality or when changes need to be identified on a regular basis. It can flag new hosts, accessible services, certificate relationships, security configurations, and technology notes. In this way, it supports discovery and prioritization prior to a targeted audit.<\/p>\n<p class=\"wp-block-paragraph\">The method has its limitations. A detected vulnerability does not automatically belong to the organization. Publicly visible technology indicators do not necessarily confirm the specific version or exploitability. Internal permissions, segmentation, and inaccessible systems remain out of sight. EASM therefore does not replace authenticated scans, penetration tests, or audits.<\/p>\n<p class=\"wp-block-paragraph\">LocateRisk performs agentless analyses of publicly accessible attack surfaces and classifies findings based on KPIs. A <a href=\"https:\/\/locaterisk.com\/en\/know\/what-is-a-security-rating\/\">Security Rating<\/a> can consolidate changes. To make a decision, asset assignments, individual findings, and the business context must be reviewed.<\/p>\n<h2 class=\"wp-block-heading\">Combine methods and apply them neatly<\/h2>\n<p class=\"wp-block-paragraph\">A coordinated process can begin with EASM to identify unknown external assets and changes. A vulnerability scan repeatedly tests selected known systems. A penetration test validates prioritized scenarios in greater depth. An audit examines whether the overarching process and defined controls are being effectively implemented.<\/p>\n<p class=\"wp-block-paragraph\">This sequence is not a mandatory model. For a new, critical web portal, a penetration test may take priority before the site goes live. For a large, historically developed web presence, the discovery phase may be omitted initially. An audit may be the appropriate first step to provide contractual evidence of compliance.<\/p>\n<p class=\"wp-block-paragraph\">The scope of work should include the key question, in-scope and out-of-scope systems, the level of testing, access, testing time, security limits, data handling, validation, and report format. Also agree on how critical findings will be reported immediately and who will approve corrective actions. To establish a structured starting point, the <a href=\"https:\/\/locaterisk.com\/en\/landing\/it-risk-analysis\/\">Security Rating<\/a> Prepare external evidence and prioritize.<\/p>\n<p class=\"wp-block-paragraph\">Don't judge success solely by the number of findings. Appropriate criteria include clarified asset assignments, validated high-risk scenarios, time to resolution, repeat findings, and proven effectiveness. A <a href=\"https:\/\/locaterisk.com\/en\/landing\/free-rating\/\">Free Rating<\/a> can indicate which external perspective is relevant to the subsequent audit plan.<\/p>\n<p class=\"wp-block-paragraph\">Be sure to plan for the handoff between processes. An EASM note should be assigned to the scan or test with a unique asset ID. A validated penetration test finding requires an owner and a deadline. An audit should be able to verify whether the remediation and follow-up were documented. Consistent asset IDs, risk classes, and status values prevent the same observation from being addressed multiple times without context.<\/p>\n\n<div class=\"wp-block-lr-faq-module\"><div class=\"content\"><h3>Frequently asked questions<\/h3><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">What is the difference between a vulnerability scan and a penetration test?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">A vulnerability scan primarily uses automated methods to search for known vulnerabilities within a defined scope. A penetration test examines, to an agreed-upon depth, whether and how selected vulnerabilities can be exploited in practice or linked to attack vectors.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">Can EASM replace a penetration test?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">No. EASM identifies and monitors external assets and exposures. A penetration test validates selected attack vectors in greater depth and under detailed authorization rules. EASM can prioritize suitable targets and scenarios for further testing.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">When is a security audit advisable?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">An audit is appropriate when defined requirements, processes, and controls need to be assessed against verifiable criteria. A technical test is often more suitable for determining the practical usability of a specific application.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">What authorization is required for a penetration test?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">He requires a written scope of work that specifies target systems, permitted techniques, timeframe, test accounts, data rules, emergency contacts, and termination criteria. Third-party providers or cloud platforms may impose additional requirements.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\">How often should these procedures be performed?<\/a><img class=\"collapse-toggle\" srcset=\"http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,http:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">The frequency depends on risk and changes. Scans and EASM are suitable for recurring checks. Penetration tests are useful before critical releases, after significant changes, or on a risk-based basis. Audits are conducted based on control and verification requirements.<\/p><\/div><\/div><\/div><\/div>\n\n<p class=\"wp-block-paragraph\">Would you like to determine which procedure is best suited to your current security concern? <a href=\"https:\/\/locaterisk.com\/en\/landing\/it-risk-analysis\/\">Discuss the scope of an external IT risk analysis with LocateRisk<\/a> and plan the appropriate next steps.<\/p>","protected":false},"excerpt":{"rendered":"<p>Comparison of vulnerability scans, penetration tests, security audits, and EASM based on criteria such as scope, depth of testing, authorization, timing, and results.<\/p>","protected":false},"author":6,"featured_media":0,"template":"","wissen_thema":[818],"class_list":["post-99021","wissen","type-wissen","status-publish","hentry","wissen_thema-easm-angriffsflaeche"],"yoast_head":"<title>Schwachstellenscan oder Penetrationstest \u2013 LocateRisk<\/title>\n<meta name=\"description\" content=\"Schwachstellenscan, Penetrationstest, Security Audit und EASM vergleichen: Ziele, Scope, Pr\u00fcftiefe, Autorisierung, Zeitpunkt und Ergebnisse.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/locaterisk.com\/en\/know\/vulnerability-scan-penetration-test-security-audit-easm\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Schwachstellenscan oder Penetrationstest \u2013 LocateRisk\" \/>\n<meta property=\"og:description\" content=\"Schwachstellenscan, Penetrationstest, Security Audit und EASM vergleichen: Ziele, Scope, Pr\u00fcftiefe, Autorisierung, Zeitpunkt und Ergebnisse.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/locaterisk.com\/en\/know\/vulnerability-scan-penetration-test-security-audit-easm\/\" \/>\n<meta property=\"og:site_name\" content=\"LocateRisk\" \/>\n<meta property=\"og:image\" content=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_Generisch_03-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1080\" \/>\n\t<meta property=\"og:image:height\" content=\"1080\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/wissen\\\/schwachstellenscan-penetrationstest-security-audit-easm\\\/\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/wissen\\\/schwachstellenscan-penetrationstest-security-audit-easm\\\/\",\"name\":\"Schwachstellenscan oder Penetrationstest \u2013 LocateRisk\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#website\"},\"datePublished\":\"2026-09-03T07:00:00+00:00\",\"description\":\"Schwachstellenscan, Penetrationstest, Security Audit und EASM vergleichen: Ziele, Scope, Pr\u00fcftiefe, Autorisierung, Zeitpunkt und Ergebnisse.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/wissen\\\/schwachstellenscan-penetrationstest-security-audit-easm\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/locaterisk.com\\\/wissen\\\/schwachstellenscan-penetrationstest-security-audit-easm\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/wissen\\\/schwachstellenscan-penetrationstest-security-audit-easm\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/locaterisk.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Wissen\",\"item\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/wissen\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Schwachstellenscan, Penetrationstest, Security Audit oder EASM: Welches Verfahren passt?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#website\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/\",\"name\":\"LocateRisk\",\"description\":\"IT-Sicherheit messen und vergleichen\",\"publisher\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#organization\",\"name\":\"LocateRisk\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/Kettenglieder_V0216-9.jpg\",\"contentUrl\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/Kettenglieder_V0216-9.jpg\",\"width\":1920,\"height\":1080,\"caption\":\"LocateRisk\"},\"image\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/locaterisk\\\/\"]}]}<\/script>","yoast_head_json":{"title":"Vulnerability Scan or Penetration Test \u2013 LocateRisk","description":"Comparing Vulnerability Scans, Penetration Tests, Security Audits, and EASM: Objectives, Scope, Level of Detail, Authorization, Timing, and Results.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/locaterisk.com\/en\/know\/vulnerability-scan-penetration-test-security-audit-easm\/","og_locale":"en_US","og_type":"article","og_title":"Schwachstellenscan oder Penetrationstest \u2013 LocateRisk","og_description":"Schwachstellenscan, Penetrationstest, Security Audit und EASM vergleichen: Ziele, Scope, Pr\u00fcftiefe, Autorisierung, Zeitpunkt und Ergebnisse.","og_url":"https:\/\/locaterisk.com\/en\/know\/vulnerability-scan-penetration-test-security-audit-easm\/","og_site_name":"LocateRisk","og_image":[{"width":1080,"height":1080,"url":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_Generisch_03-1.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/locaterisk.com\/wissen\/schwachstellenscan-penetrationstest-security-audit-easm\/","url":"https:\/\/locaterisk.com\/wissen\/schwachstellenscan-penetrationstest-security-audit-easm\/","name":"Vulnerability Scan or Penetration Test \u2013 LocateRisk","isPartOf":{"@id":"https:\/\/locaterisk.com\/de\/#website"},"datePublished":"2026-09-03T07:00:00+00:00","description":"Comparing Vulnerability Scans, Penetration Tests, Security Audits, and EASM: Objectives, Scope, Level of Detail, Authorization, Timing, and Results.","breadcrumb":{"@id":"https:\/\/locaterisk.com\/wissen\/schwachstellenscan-penetrationstest-security-audit-easm\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/locaterisk.com\/wissen\/schwachstellenscan-penetrationstest-security-audit-easm\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/locaterisk.com\/wissen\/schwachstellenscan-penetrationstest-security-audit-easm\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/locaterisk.com\/"},{"@type":"ListItem","position":2,"name":"Wissen","item":"https:\/\/locaterisk.com\/de\/wissen\/"},{"@type":"ListItem","position":3,"name":"Schwachstellenscan, Penetrationstest, Security Audit oder EASM: Welches Verfahren passt?"}]},{"@type":"WebSite","@id":"https:\/\/locaterisk.com\/de\/#website","url":"https:\/\/locaterisk.com\/de\/","name":"LocateRisk","description":"Measure and compare IT security","publisher":{"@id":"https:\/\/locaterisk.com\/de\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/locaterisk.com\/de\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/locaterisk.com\/de\/#organization","name":"LocateRisk","url":"https:\/\/locaterisk.com\/de\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/locaterisk.com\/de\/#\/schema\/logo\/image\/","url":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_V0216-9.jpg","contentUrl":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_V0216-9.jpg","width":1920,"height":1080,"caption":"LocateRisk"},"image":{"@id":"https:\/\/locaterisk.com\/de\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/locaterisk\/"]}]}},"_links":{"self":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen\/99021","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen"}],"about":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/types\/wissen"}],"author":[{"embeddable":true,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/users\/6"}],"version-history":[{"count":1,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen\/99021\/revisions"}],"predecessor-version":[{"id":99029,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen\/99021\/revisions\/99029"}],"wp:attachment":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/media?parent=99021"}],"wp:term":[{"taxonomy":"wissen_thema","embeddable":true,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/wissen_thema?post=99021"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}