Really depends on the network. For example if you do not have mail servers in dc or on perimeter then there is no point checking for the Anti-spam blade or the MTA setup. Or if you do not have SMB shares then you can skip that in the inspection for AV blade(and other blades) Same for FTP.
I don't think there is a general advice like 'if you must protect DC enable the following blades' Because you can have anything or almost nothing in a DC. Personally, I would go for all the threat prevention blades in combi with app and URL filtering. (Of course HTTS inspection, very important)
-------
If you like this post please give a thumbs up(kudo)! 🙂