Containment
Stopping an incident from spreading further while you work out what happened.
Containment buys time. Isolating affected machines, disabling compromised accounts, and blocking attacker infrastructure limits the damage before you have full understanding, which you will not have early on.
There is a trade-off with evidence. Pulling the power destroys memory-resident evidence that would explain the intrusion, so network isolation is usually preferred over shutdown.
Where this comes up
Containment sits inside our cybersecurity and threats work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.