Short answer
HubSpot's developer docs: a reverse proxy gives more configuration options but needs significant operational knowledge, and your IT team must maintain custom headers, SSL certificates and cache rules; HubSpot's support doesn't cover the proxy. Use the origin CNAME from the setup guide (format .sites-proxy.hscoscdnXX.net), not the SSL pre-provisioning CNAME. Cloudflare Enterprise can use an Orange-to-Orange setup.
1. Domains
Domains settings in my demo portal.

2. Simpler option
A subdomain such as blog.example.com needs no proxy. See subdomain or new domain.