Sorry I didn't make time to answer to all yet, but quickly this: https://wiki.archlinux.org/index.php/disk_encryption#Data_encryption_vs_system_encryption
It suggest to (at least) take care of /tmp and /var, and all this is only for online tampering.
