As a starting point, the protection layer has to have a higher privilege level than the operating system, e.g. hypervisor.
Every method requires an entry point. Like re-flashing an device requires an uncompromised bootloader. You would need an entry point very close to the hardware.
I would say its possible, but not realistic except for very simple devices.
Yeah, when you have a rootkit that's active, there are signals you can look at to claim from a range of "there is most certainly a rootkit" to "there is a small possibility that there is a rootkit".