Let's start with the main question. Can hackers use DNS? the answer is yes. We just had a TechTalk about DNS security, you can watch it here: https://community.checkpoint.com/t5/General-Topics/Hacking-DNS-TechTalk-Video-Slides-and-Q-amp-A/m-p...
Now, you can also adjust and log implied rules. DNS is NOT enabled through the implied rules by default.

You can also create explicit rules to control your DNS traffic. Lastly, with Threat prevention, you can put additional protections over DNS traffic, regardless of how you configure your rules, implied or explicit.