I use HIPS "Smart Mode" Plus some manually added basic Reg Protection rules set to "Ask". The issue is when I found a confirmed malicious activity coming from an infected process. And I am asked by HIPS to allow or block this activity, I can perfectly deny it. But it does not mean that the malicious process wil be terminated and move to quarantine, so it won't be able to start again. In this picture the option if selected, would end and quarantine the pcoess "clt.exe".