Sure but what is the reason? Is it just “I want maximum available security on this computer”? Or is there a known exploit?
As you put it, it really is a desire for maximum security at play here.
Booting that computer from an external drive with third party kexts would also increase the attack surface, right?
"Just allowing kexts to be loaded" sure, it wont. But "just allowing kexts to be loaded" makes no sense as an action, unless you also actually intend to and do load at least one kext.
In which case, it absolutely increases the attack surface.