There are some other ways to abuse Trusted executables to bypass auto-containment in CIS.
For example, the LOLBas project shows many LOLBins that can run DLLs. Some of them, like rundll32.exe or regasm.exe, can be hardened via Comodo Script Analysis, but most are not included, and some can be used to bypass CIS via a malicious MSI installation that runs one of those LOLBins + a malicious DLL.
In this scenario, the DLL does not have to be a false negative.
However, this could possibly happen in a highly targeted attack (no worry for home users).