Yes, it's an exact match check.
You can also use the memberOf attribute if you want to match on the entire DN of the group.
AD stores both security and DLs in the memberOf context, so no, there is really no way to limit it. I can't imagine a DL and security group would have the same name.