Can someone clarify the defining difference between these two concepts? I seem to have difficult distinguishing between them and often answer questions on practice tests incorrectly regarding these.

Is there a specific time that vulnerability scanning is used? Apparently it is done when assessing security policies.

:
When is penetration testing done? Is it after new policy has been enacted to ensure it is up to snuff?

:
I am taking the test on the 27th and have finished Lammle's and Meyer's material. I feel okay about it but still somewhat nervous. Getting some clarification would help ease my anxiety.