Understanding DNSSEC validation using Pi-hole's Query Log

These DNSSEC queries are generated internally by FTL and are directly sent (in contrast to going the usual way through the operating system resolver routines). This also helps you telling them apart from other queries done on the same machine (localhost) but another process.

Only if you are sure nothing is using unbound in your home network (unlikely to happen). You gain nothing but some more insight, the protection should be the same*.

*) Plus/minus some bugs that can always be there. Without this option, you have both unbound and Pi-hole do the validation. This is basically guaranteed to catch any false-positives whereas taking unbound out of the equation, theoretically, reduces the level of protection from two to one (pseudo-units).