I encrypt all my filesystems, boot partitions excluded. I started with my work laptop. It made the most sense because there is a real possibility that it gets lost or stolen at some point. But once I learned how simple encryption is, I just started doing it everywhere. It’s probably not gonna come into play ever for my desktop, but it also doesn’t really cost me anything to be extra safe.
Generally, you don’t. You can look for some benchmark to try and find a difference between them, but if you don’t notice a difference in your day to day tasks, then it’s all the same. In my experience you should pick a kernel based on your desired experience. For my needs this is how the kernels differ: