On the use of mapping:
No need to burn IPs routing them - no gateway or broadcast.
Can either forward everything, unwise, or specific ports.
The LAN is a simplification in the diagrams. There are other VLANs not featured. The DMZ using the public IPs is a /28: no public IP mapping to hosts in the subnet where the regular devices live, those are masquerade / SNAT only.