In the global rules, by default, the FW blocks all inbound connections to protect you computer. So unless you make yourself inbound rules for specified apllications, you won’t receive inbound connections. if a hacker tries to enter your computer, he’ll be blocked by the FW.
Note that this global rule of blocking inbound connection won’t prevent the application which needed it to update. Why? Because the update is initiated by your computer and as such it is an outbound connection even if files are downloaded to your computer
Outbound connection : your computer connects to an external IP adress and receive an answer
Inbound connection : an IP outside your LAN tries to connect to your computer