What mode is the AFM configured in, ADC or Firewall mode? ADC mode has implicit rules for existing VSs but in Firewall mode you need to explictly create firewall rules. Normally i'd recommend ADC to start with and then move over to Firewall mode once all rules in place. It sounds like the Global Drop context is dropping your traffic if you have to use Accept Decisively, although i can' t be sure. You may need to enable logging for the Global context by enabling a DB key -
tmsh modify sys db tm fw.globaldefaultrule log value enable
This might give you more information on why the traffic is being dropped.
As for reasons to use context, then it helps when understanding the firewall requirements on a per application (i.e. per VS) instance. If everything was in the global context you don't have this visbility necessarily.
Hope this helps,
N