That doesn’t look right. I have all but a couple ports disabled in Global Rules, and when the application that listens to these ports isn’t running, my PC looks completely stealth to GRC’s Shields Up.
IIRC, after installation CPFv3 didn’t have the last “blocking” global rule that would block any traffic not mentioned previously in the list (v2.4 did have it). So, “out of the box” it didn’t really block incoming connections on the system level. Check whether you have one there.