umm,
svchost.exe was set as "outgoing only" at first. For
system I must allow certain types of incoming connections from our local lan (as in picture 2) so I can not set system as "outgoing only". As mentioned, at some point it appeared that by allowing (no logging) ICMP incoming (picture 3) CIS is actually blocking & logging (exactly opposite to the rule) ICMP incoming...which is what was aimed from the beginning.
Updateshort summary of what's encountered so far for
svchost.exe ruleset => what's CIS actually doing:
0. "out-going only" standard ruleset => ask for each incoming ICMP attempt
1. block (no logging) all incoming ICMP connections rule (above the "standard out-going only" pattern - "allow all outgoing TCP/UDP" and "block all incoming/outgoing IP" at the bottom) => ask for each incoming ICMP attempt
2. allow (no logging) all incoming ICMP connections rule (above the "standard out-going only" pattern) => block & log each incoming ICMP attempt, (this is new) ask for each out-going ICMP request
3. rule from 2. above rule from 1. (both above the "standard out-going only" pattern) => from time to time ask on ICMP incoming connection, from time to time - block & log incoming ICMP connection - here the mess is full
Update iWith all mentioned settings (what's common is obviously the "out-going" pattern at the bottom which is supposed to silently allow all out-going TCP/UDP requests...) I'm asked from time to time for out-going UDP requests. Another one

PS
Rules which are at the
system ruleset were automatically generated when networks were detected after install (allowed access for comps in the network), haven't touched them since. The ICMP incoming connections (logged/asked for
svchost.exe) are from computers exactly from these zones.