Regarding DDos attack, We are unsure why we are unable to select all the rules listed over here.

Is it something default which are part of this DDos attack? Don’t we need to apply explicitly?

These are overrides. By default all rules are on and set to high for maximum protection. You do not need to do anything to add protection. Overrides are used to turn things down or off if your real traffic has a particular signature that gets blocked by default and you want to allow it.

Some rules cannot be overridden and are read only as you have found.

