NTP is trivially MITM. Secure NTP is basically not deployed anywhere. Someone with a google.com cert that's valid other than expiration is probably google and probably has a working clock.
You can always use a gpsd(4) compatible USB dongle as the time source.
Or run their own NTP server. That's what I do in my home network.
Sure, if you have such a dongle, and it has sufficient view of the sky. Adding a 'free' https based sanity check on top of NTP seems like a good balance of cost vs reward.
gps (and friends) is a nice way to get access to a very accurate timesource, but it's not always worth the cost.
GPS doesn't send full time. It wraps every 1024 weeks, or about 20 years, hence you need a (very) rough basis in case the system is over 20 years old.
It is a sanity check to protect against malicious ntp actors.