During an EDR containment action, an analyst isolates several servers and records the affected users. After the incident is closed, a manager asks why the report must include those isolation details. Which reason best explains why this documentation is required?
Select an answer to reveal the explanation.
Short Explanation
Think of containment notes as the flight recorder for your incident. If you don't record why EDR isolated those hosts and users, nobody can safely review the call or bring systems back. The right reason is accountability and recovery, not scanner data or legal shortcuts.
Full Explanation
Containment reports exist to create a defensible record of what was stopped, when, and under what assumptions. When an EDR agent isolates hosts and identifies affected users, the report lets reviewers compare the decision against evidence, detect over- or under-containment, and guide recovery with known scope. It also supports handoff because recovery teams need to know which systems were isolated and which accounts were involved before restoring access or removing controls. The idea that the report proves the SOC isolated every endpoint that generated any alert is wrong; documentation should record justified actions, not encourage blanket isolation that can disrupt business operations. The idea that the report lets legal bypass change control or validation is wrong because legal and forensic requirements increase scrutiny, not remove change management. The idea that the report supplies CVE data for automatic prioritization is wrong because containment records describe endpoints and users affected by an incident, not vulnerability metadata from scanner findings. Exam caveat: For containment documentation, choose review, accountability, and recovery, not automation or legal shortcuts. Operational check: After closure, compare the containment log with EDR history, ticket timestamps, and recovery tasks to confirm every isolated host and affected user was recorded and released.