You can't enumerate sub domains via DNS (except if you use DNSSEC with NSEC algorithm, but nobody do that).
It does not prevent people guesssing it tough.
It does not prevent people guesssing it tough.
There's a hack to prevent this that seeds the zone with false entries, but it requires the server to operate as an online signer. Since this is essentially incoherent to the design of the protocol (which makes major cryptographic and usability sacrifices to enable offline signers), there's an "NSEC4" being worked on now.
DNSSEC is silly.