One forest with multiple domains could run AAD Connect successfully: Single forest, single Azure AD tenant
For Exchange HCW, you need to choose an Exchange server as end point, so even if you are running HCW at "sub2.hq.local", you still need to choose "sub1.hq.local" as the endpoint, due to Exchange hosted on it. (It is same to run HCW on sub1.hq.local)
If you want to use "sub2.hq.local" as the endpoint, you need to install an Exchange on it coexist with another Exchange server. Then choose this new Exchange as endpoint.
Another thing you need to pay attention to: ".local" domain isn't supported hybrid, you need to change it to ".com" before running HCW.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.