This is fine. You only need one of the two.
Nowhere.
That config is just telling nginx to take files from /usr/local/etc/nginx/letsencrypt
when someone asks for example.com/.well-known/acme-challenge/
I am not sure it is needed, I think it isn't.