During containment, you first pinpoint exactly what malware or attack vector is in play and how far it has spread - i.e. identifying the threat. Then, in the eradication phase, you eliminate the root cause by removing the malicious threat (malware, backdoors, unauthorized accounts, etc.) before moving on to system recovery.