1) No, not even close.
2) Disconnect from the network. This, of course, won't stop local attacks on the AMT or ME.
This is why I've been complaining about the ME forever. Forcing a privileged black-box that can't be disabled in to every CPU is... not suspicious all.
Even worse are some implementations. I have a Supermicro all-in-one MB that I used in building a home storage server. It has two gig-ethernet ports. About two months ago, I was rearranging around the machine, and when I plugged it back in, apparently I switched the ethernet port plugged in to the switch to the "primary" interface.
And one of the monitors goes off a few minutes later - there's a new network device on my private network. Turns out a web interface to the ME comes up automatically when using the primary NIC - it got a DHCP lease and was happily waiting to be managed - with the default creds ADMIN/ADMIN.
I thought that we had that one figured out, but apparently not. Yes, I should have read the manual for the motherboard, but that's beyond absurd. And, I guess, a good reminder to trust nothing.