Every HIPS alert you choosed, treat as "Isolated Application"..if you love this option. I suggest you to disable HIPS
Sandbox will cover all unknowns as isolated.
Internet Security Configuration settings are maintained for new Comodo users to bring more usability beside default-deny machanism. (in the video)
I never face an infection with "Proactive Security" configuration (HIPS: off) others are default.
Try to get infected
Signatures is not good but in this video I think Comodo AV performed good against your URL downloads. I actually like this kind of videos more than detection tests
Thanks
@safe1st