Yes because it is the way that NTFS permissions work.

The root/administrator account can go anywhere within the file system (as it should be) By unticking "use simple file sharing" and changing the folder permissions (which I think you need to be an admin to do) you are saying "windows ignore your default permissions I can look after this myself"

This is because either you wish to delegate permissions and/or you have your users in the correct groups.

By adding a user you do not trust to the local administrators group, you are asking for trouble. It is not a problem with windows a "hack" or even a work around it is what happens when people add normal users to admin accounts.

If you need a local user to have admin access and wish to secure your files use truecrypt.