If you use 3cx fqdn - all fqdn dns updates and lets encrypt ssl renewals are taken care of thru 3
Custom fqdn - you managed your own dns and updates of the ssl certificates - extra work for you
No technically reason to use your own fqdn - unless your company wants the web url (mangement, client web), and remote devices to have your own fqdn
No difference in security
You can only use your own fqdn on pro or enterprise license