I block all that via firewall, authoritative DNS and gateway on home network. It works very well. Trying to accomplish this via an app on an un-rooted iPhone would be a headache, IMO, and ultimately is subject to defeat by Apple if they so choose. As seems to be the computing paradigm du jour, Apple more or less has "remote control" over these devices, whether through automatic updates, their control over an AppStore or some other mechanism.
When someone buys an iPhone, there is an expectation that an ongoing relationship with the company is created. It is assumed every purchaser wants to use Apple's time servers, Apple's messaging service, Apple's cloud storage, Apple's software review process, etc. and there is no opt-out. Consequently the purchaser is expected to establish a means to identify themselves to the company (AppleID) in the future. Fingerprints may be collected, facial recognition, etc. Apple has the means to know its hardware customers, very well. It does not really feel like we own the hardware. More like a lease or rental. Feels like we are being used as a source of further revenue generation. A massive user base tethered to the company that it can use as a bargaining chip to make deals with other companies.
Here is a different approach. Imagine you have two mobile devices. 1. An iPhone. 2. A portable computer running an open source OS that can act as firewall, authoritative DNS server and/or gateway. Apple has no control over #2. #1 can only access the internet through #2. #2 belongs solely to the user and it is controlled by the user, not any company.
Perhaps one day we will see Apple controlling the user's routing table and any network settings entered by the user will be subservient to Apple's.