I wonder if the wording is wonky, but the meaning is technically correct: Not the data itself, but rather key management. The first two methods, 4-digit or complex password, will store a password-encoded key on iCloud. The second "don't create a security code" will not store a password-encoded key on iCloud. The key will instead be transferred via LAN, thus why it needs approval from another local device that has it.
This is just a hypothesis, I wonder if it's true?