Full Strict just means that CF verifies your origin cert against actual CAs (or the private CA they issue you a cert for). "Full" means they don't verify the certificate authority of your origin, which technically is _a lot worse_ because that means you could be getting silently MITMd by some middlebox, since Cloudflare will accept whatever self-signed certificate your origin presents.
For almost all of Cloudflare's features. CDN, WAF, and all the compute features require seeing, storing, and caching content in plaintext. CF doesn't have much of a value proposition if all they're doing is handling Layer 3/4 DDOS prevention (most DDOS hits even back in 2015 were done on the protocol layer, or at least most DDOSes that actually showed up or impacted the underlying service).