can't really protect against DDOS thats more of a datacenter objective, SQL injects are done via scripts I beleive so if you only install trust worthy scripts you should be okay.
Install Brute Force Detection and Mod Security if you'd like. Don't install scripts or modifications you dont need, make sure your software is always at the latest verisons