Most organizations with a mature IT security program understand the requirement to perform vulnerability assessments and penetration tests.
A good penetration test will attempt to exploit the vulnerabilities identified in a vulnerability assessment. These observations can then be prioritized and presented to the client for remediation.
A Red Team assessment, by contrast, provides further insight into the organizations overall security posture by simulating an advanced threat actor with specific goals in mind. With a much broader scope than a typical pen test, a red team assessment allows you to explore the real-world risks the client is exposed to. Multiple non-critical vulnerabilities may be utilized to achieve the goal in question therefore highlighting the requirement to view security from a holistic perspective.