Like LiteSpeed Enterprise did.
I mean DOS/DDOS layer 7 attacks that target usually PHP/MYSQL and the web server.
With LEMP setup, usually PHP-FPM crash or die.
Essentially, a mod security engine would allow the server to filter requests based on a rule set. If the request is a bad/dangerous request, it is denied.