That's correct order and expected behaviour.
I have something else to add.
You could use the McAfee Installation designer and customize the policies and Settings, so your VSE will be installed with the same configuration than ePO, in case you have any exclusions or diferent Settings.
In my case I want only to protect the machine during the first phase (domain join, os configuration ecc..), so also if there are no exclusions and the default settings are applied (scan all files, archive ecc..) I'm not worried about performance issues.
Furthermore, in my case, I don't remove any components (email scanner, ecc..) also from the VSE install task pushed from ePO .Simply I disable it from the policies..
But this is another topic: which are the best practices regarding the VSE component ? Is better to remove it if unused, or is better to leave it (for future use for example) in the installer and disable it from the policies?
After this phase I will connect the network cable and so the McAfee agent will sync all the policies (Mcafee Agent and VSE) from the ePO.
But yeah, I agree with you, very good suggestion!