They should - high entropy dns names and frequent subdomains should be indicators to watch for. The bad news is they can be noisy and not get the attention they deserve (never saw a SOC that wasn't swimming in alerts).
Depends on what a host is supposed to do. A mail server is going to make a lot of random DNS queries.
I’ve never seen anyone try and setup alerts for random DNS queries. If you’re in the position to know what domains are good, then why not simply use a whitelist?
Besides, even if you saw these queries you’d have no easy way of know I’d they were malicious or not.
Some IDS systems do it for you
I was using Darktrace at my last job and it would tell us when servers started querying domains they don't usually query so there are products that do it
Those systems usually flag based on a known set of “bad” domains, which wouldn’t stop this attack (they could just register a few new domains before starting the attack).