After some further investigating and experimenting, I have answered most of my questions. The first problem I had was my misunderstanding of how Download Insight is invoked. I realized that it may not really intervene until the downloaded software is executed. Once I figured out that the popup from Download Insight appears after I try to execute the software, I was able to manipulate through policy change how SEP responds. I set the policy to "5" and changed the setting for unknown software to log, prompt, quarantine and delete to see what would happen. I then saw the corresponding reputation events in the risk log on the local client and on the SEPM. My next step is to get approval to implement the policy to delete unknown files in production. I believe that once I do this, these files that continue to get redetected will be deleted.
The challenge for me to understand the functionality was the two sets of popups I have seen when trying to download unknown software. One set is invoked when I try to install software that was successful downloaded. Another set of popups sometimes appears temporarily which indicates that the download itself was blocked. Both sets reference download insight. I included a screen print of each to show the two examples.