1) Keeping wifi on: someone could create a wifi network & password that is the same as one saved on your phone--your home, hotel, work. So your phone connects to their wifi network. Then they try and do stuff to your phone.
There's probably other issues that are rare to happen to the average joe.
3) Wifi scanning only lets services and apps turn on wifi momentarily to scan for networks. If you have location services use wifi APs to help determine your location then you would need both settings on. I'm pretty sure GOS won't turn on the wifi periodically to check if there's any saved WIFIs to connect to. It'd defeat the purpose of turning wifi off automatically.