The problem is, the request still hits Apache, so you can still get DDOSed. A proper WAF will drop requests before they hit the web server software, or even better, before hitting the server at all.
The problem is, the request still hits Apache, so you can still get DDOSed. A proper WAF will drop requests before they hit the web server software, or even better, before hitting the server at all.