Block at first sight applies to executables and non-portable executable files (such as JS, VBS, or macros) applies only when they have the Mark Of The Web (are downloaded from the internet by a browser which sets the MOTW).
ASR rule Block executable files from running unless they meet a prevalence, age, or trusted list criteria applies to ALL executables
Cloud delivered protection level Zero Tolerance (your block option)
Block at first sight and cloud delivered protection level are mentioned explicitly as two different mechanisms (
link Microsoft)? In the documentation of Block at first sight the reference to MOTW only is explained explicitly. While this is not mentioned explicitly at Cloud Protection Level. These settings are controlled by two different settings in group policy. That is why I assumed Cloud Protection Level applies to all executables.