← CCNP Security: SCOR core and operations
07 / 8 · 40 MIN

Endpoints, detection, and containment

Use telemetry to investigate and separate containment from recovery.

Concept and mechanism

Prevention and EDR complement each other. Blocking a known file does not remove the need to observe behavior and investigate later activity. New intelligence can reclassify earlier evidence, so a retrospective alert does not necessarily mean a recent arrival. Analyze trajectory, process, and time together. Isolating an endpoint limits communications and may retain intended management paths, but it neither reinstalls the system nor automatically removes the cause. Recovery needs its own criteria. Dynamic analysis without detection also has limits: it observed behavior only under test conditions. Correlate other evidence before turning that result into a universal safety guarantee.

Guided application

In a fictional near-close scenario, the playbook authorizes containment and a rehearsed alternate execution path exists. Coordinate isolation, preserve evidence, and activate continuity with owners; do not indiscriminately restart every server. Before handing EDR to RUN, reconcile inventory with recent telemetry: two hundred managed devices and one hundred seventy active ones leave thirty needing explanation. Missing telemetry does not prove compromise, but it should not disappear from the denominator either. If a batch loses performance, measure and rehearse a justified minimal exception instead of excluding the entire disk. For email, distinguish classification from remediation: detecting phishing with No Action does not demonstrate quarantine or absence of user access. Record the outcome of every action the procedure promises.

IN PRACTICE

Confirmed isolation is a containment step rather than a sufficient closure criterion.

Common pitfalls

Inventory as active coverage; unknown as safe; isolation as eradication; detection as remediation.

Related topics: Risk, identity, and AI security · Encryption, VPNs, and APIs · Firewall, inspection, and layer-two protection

Take this idea with you

Retain evidence, coverage, and return-to-service criteria.

Create account

Reference: Secure Endpoint best practices · 350-701 SCOR v2.0, effective 2026-08-27; core component of CCNP Security