Ransomware vs CIS = Fail?

One of the suggestion to increase security with CIS is to modify the rule for unknown files to run virtually and untrusted.
Unfortunately this is not possible on Windows 10:
https://forums.comodo.com/resolvedoutdated-issues-cis/limited-and-restricted-block-screen-capture-but-untrusted-does-not-m399-t95001.45.html

Personally, I have set the auto-sandbox rule to block unknown apps.
Like that I can right-click on the app and run it in Comodo sandbox.
It seems that manual (on-demand) sandbox is more restrictive than auto-sandbox: