Exclude some pages when in "Under attack" mode

We’ve enabled “under attack” mode. But is it possible to exclude some pages from DDoS protection when we’re in this mode?

We don’t want to “CLoudFlare validation” page to be displayed in this “Under attack” mode when some specific pages are requested (actually they are web-services so should work without any validation)

That could work with a page rule, setting a different security level, however you might also have to approach it from the other side. Setting a non-IUA level as default and the use page rules to set IUA for those paths where you want it to be active.

