I think there are two things to keep separate:
- SFDC Leads & Contacts syncing to Marketo
- Marketo Leads syncing to SFDC Leads
For the first item you need to adjust SFDC security settings so Marketo only has access to the Leads you want (e.g. this is a great way to keep Leads/Contacts with no email address out of Marketo).
For the second item, read Steven's write-up above. Indeed, it's often easier to sync all net new Leads in Marketo to SFDC but mark them as "raw" until they are qualified. If that doesn't work for your specific situation, you can sync Leads only when they are qualified. In both cases, it is preferred to create a central Smart Campaign that syncs net new leads based on your criteria.