She is a beginner in the security matter. She uses the computer for the standard tasks and does not install new programs. All updates are performed via Windows Updates, Microsoft store, and scheduled tasks. All applications are installed in 'Program Files' and can run only as standard user (elevation not allowed).
In the locked setup the user cannot install/run new executables and scripts. The scripts and executables are blocked by SRP in all locations, except: Windows, Program Files, and Windows Defender folders. The user (also exploits and payloads) cannot copy/change/replace files in Windows, Program Files and Windows Defender folders because that would require elevation.
I configured also Adguard DNS for safe web browsing. For viewing documents, I installed Universal Apps (Word Mobile, Excel Mobile, PowerPoint Mobile and Adobe Touch) which run in AppContainer. For document editing, I installed SoftMaker Office (no macro support or DDE vulnerability).
The identical setup is installed on my father's computer. He is a total beginner.
The locked SUA is silent and very secure. The user can run what is prepared for running. Everything can update without user intervention and the user has no problem with choosing between allow or block.