It really depends on your download habits. If you strictly install apps from the Google Play Store, Play Protect is generally sufficient and that McAfee add-on is mostly bloatware.
However, if you ever sideload apps or download APKs from third-party sites, relying on a single built-in scanner isn't enough. A protocol over at TheHappyMod is to run any raw APK binary through VirusTotal to check it against 65+ heuristic engines simultaneously. A single engine (like the one Samsung bundles here) can easily miss newly compiled malware or throw false positives on harmless mods.
If you sideload, skip the built-in Samsung toggle and verify the file's SHA256 checksum and VirusTotal report before you ever hit 'install'.