Pen tests aren't cheap. Even basic ones are ~$20k. There's only 2 types of companies that bother with them: ones that care about cybersecurity and ones that have to do it for compliance (PCI/CMMC/etc). Both will have some kind of IDS and a SIEM.
Most folks dgaf about certs, and I agree with them. Certs are BS. I only have certs because employers paid for them and in tech (especially security) there's a LOT of free time if you know what you're doing. Certs only prove you can pass a test.
Bold of you to assume most companies have intrusion detection systems and that their monitoring isn't muted half the time.
Findings come from an automated report generated by a scanner that does literally all the work.
OP post is really not that far off. It's an easy gig.