Hi,
1) actually, enabling “customized htaccess” should do the job. But in your case as this seems to not work, the other way is to change permission of htaccess file to read-only.
2) you can be hacked because of numerous ways. HMWP renames default WP paths so that wordpress is hidden. Also it has IDS, which blocks intrusions (harmful requests) coming to your site. But this alone will not guarantee that the site will not be hacked. We also recommend you to use Wordfence plugin along with HMWP for enhanced security. And scan your site for malware infection too.