People often use penetration testing and red teaming as if they meant the same thing. They share techniques, but they answer different questions.
A penetration test asks what weaknesses exist in a system and how serious they are. It is scoped to specific applications or networks, runs for a defined period and aims to find as many issues as possible.
A red team engagement asks whether a determined attacker could reach a specific goal, and whether you would notice. The goal might be access to customer data or control of a critical system. Testers use whatever routes work, including phishing, exposed services and physical access, while trying to avoid detection.
That difference changes what you learn. A penetration test gives you a broad list of fixes. A red team gives you evidence about how your people, processes and tools work together under realistic pressure.
For most organisations, penetration testing comes first. If your applications and networks still have basic weaknesses, a red team will find them quickly and teach you little you did not already suspect.
Red teaming is most valuable once you have a working security team, some monitoring in place and a wish to test whether it works. Purple team exercises, where attackers and defenders work together, are a good bridge between the two.
If you are unsure which fits, start with the question you want answered. If it is what is wrong with this system, choose a penetration test. If it is whether you can detect and stop a real attack, that is a red team question.