Whilst that also makes sense, I believe that the difference is that whilst WD could have a passive limited Periodic Scanning (on-demand scan). But the windows firewall can only be an active application, either on or off.