It doesn't.
Have you ever been ddos'd? I haven't.
I imagine if it happens, I'll just switch off the VM.
If it's actually a problem, then I'd see what the VM hosting company recommends. Ultimately they will have something in place so that if my VM gets targeted they can isolate it.
My sites get denied service. Oh well.
I've never had anything get so popular that I actually need the tooling that cloudflare offers. I've never had anything targeted in a way that cloudflare would protect against.
If that is actually a vector in your security and reliability analysis, then yeh. It's probably the right tool for it.
And there are other competitors than just cloudflare if you actually need the protection, which should each be considered.
Great, use cloudflare or any number of other ddos mitigation services. Or get a larger peering connection and eat the ddos.