All of the provided IPS policies include protection against DoS attacks. There is no separate policy for DoS attacks. You can customize the DoS attack definitions just like you customize any of the exploit attack definitions in the IPS policies. For a given signature set, the same DoS attack definitions with the same configuration is included in all the pre-defined IPS policies. DoS customization is key to protecting a specific host or server from a concentrated DoS attack.
Trellix IPS enables extremely granular DoS protection: you can customize DoS attack definitions for the Sensor, interface, and sub-interface separately. At the Sensor level, customize the attack definitions in the baseline IPS policy. At the interface and subinterface levels, customize the local IPS policy. Therefore, you can apply customized DoS attack definitions that is exclusive for a given VLAN or CIDR traffic for a specific interface.