1) Yes, you could see it this way. MX is simply building up an AutoVPN tunnel to Umbrella where global intelligence, SSL decryption etc. take place.
2) Strictly speaking, you don't need Advanced Security on the Meraki side of things, but to be able to have a "real" SASE setup including local internet breakout for things like Microsoft 365, you'll even want to use the SD-WAN Plus license on Meraki.
Umbrella SIG Essentials would be the "low-end" license on Umbrella, but won't give you things like L7 firewalling, IPS, DLP and so on.
3) The AC Umbrella Module is managed by Umbrella itself. 🙂