why would I want to untick this?
the processes are identified by their hash, and the vulnerable processes are anyways given special protection.
So what's the risk here?
you can use it at default settings.
if you are installing on clean system, set it in learning mode for a while
then when you get the hang of it and maybe want to tweak it more, just ask about specific features that are not self-explanatory
just remember that the more you disable the various trust settings, the more prompts you will get.