1. If they didn't require local redundancy or local redundancy is not worth it, yes, they would have a single local controller connected back to a master/backup master pair.
2. If the local controller fails, nothing would work at that site, so if local redundancy is important, they would need a second controller at that site.
3. The7205 could be the master/backup master in this scenario.
4. Your design seems to be solid.