a combination; some have swap as a btrfs subvolume, some as a swapfile in root and those are encrypted, when the system boots it requests the encryption passphrase, regardless if it coldboots or restores. restores from swap are way faster than coldboot plus all your stuff is how you left it.
on some systems I have a separate swap partition outside of luks2/btrfs and that one’s unencrypted. when it restores from there, it doesn’t request the passphrase and the boot is even faster. that’s obviously less secure but my threat model is a lost/stolen laptop, I seriously doubt someone’s gonna forensic the shit out of my swap, it’s more likeky it’s gonna get wiped and sold.
to fully utilise this tech, it’s essential to set up suspend-then-hibernate, another awesome feature that’s way too cumbersome to set up. the laptop suspends for like 60 minutes and if it’s not woken up, it hibernates to disk.
if they run hardware that’s not cutting edge, by all means, that’s the best solution as a first distro.
ubuntu is important as a stepping stone. myself and everyone I know that’s on Fedora et al started with Ubuntu. we learned what’s what and how to go about doing things and after hitting the ceiling one too many times, we tried other stuff, found better havens and finally abandoned it forever.
so I’d caution against any action aimed at hurting it. leave it be and know that it’s still the most user-friendly solution out there and the one that’s most likely to “just work” for most people. it’ll convert people over, whether from Windows or MacOS. once they’ve crossed over, they’re more likely to wander further.