Hi,
1,3,4 - I believe 802.1ag is not supported on any of the campus stackable access switches (which I guess you would want if you are looking for a not a costly switch)
2 - You should always very carefully consider what switches you purchase, but just as a quick answer I would say 2960x with LAN base image would suit well, or 3650s, but these are more expensive
5 - When you configure port with "switchport protected" command (Private VLAN Edge feature), that port will not be able to communicate with any other ports also configured as protected. It will be able to talk to any other ports, that are not configured as protected
Regards,
Agris