Absolutely. Context is everything in cybersecurity. Without context, it is simply security theater.
A couple of great examples of not knowing or understanding the context are 1) not considering the entire attack chain (e.g. not knowing the parent) and 2) blocking (pretty much) anything globally.
For example, conhost.exe can be bad, but it can also be good. It all depends on the context, and what calls it.