Hello @Perry Chandler ,
Welcome to Microsoft Q&A Platform. Thank you for reaching out & hope you are doing well.
I understand that you are deploying Azure landing zones using Terraform referencing the Azure Landing Zone Accelerator GUI Configuration and you would like to know if you don't have to configure DDOS protection as Basic DDOS Protection is enabled by Default.
As mentioned in the deploy landing zones with terraform document, the DDoS Protection plan module is optional and it can deploy DDoS Network Protection, and link Virtual Networks to the plan if needed.
NOTE: The Azure landing zones guidance recommends enabling DDoS Network Protection to increase protection of your Azure platform. To prevent unexpected costs in non-production and MVP deployments, this capability is disabled in the Azure landing zones Terraform module due to the cost associated with this resource. For production environments, we strongly recommend enabling this capability.
Regarding the default DDOS protection - At no additional cost, Azure DDoS infrastructure protection protects every Azure service that uses public IPv4 and IPv6 addresses. This DDoS protection service helps to protect all Azure services, including platform as a service (PaaS) service such as Azure DNS. Azure DDoS infrastructure protection requires no user configuration or application changes. Azure provides continuous protection against DDoS attacks.
Refer: https://video2.skills-academy.com/en-us/azure/ddos-protection/ddos-protection-sku-comparison#skus
So, it completely depends on your requirement. If you have a production environment and want to increase protection of your Azure resources, you could optionally deploy the DDoS Protection plan resources using the azurerm_network_ddos_protection_plan
Terraform module as mentioned in below link:
If you are fine with the default Azure DDoS infrastructure protection, then you don't need to add the DDoS Protection plan module to your Terraform installation.
Kindly let us know if the above helps or you need further assistance on this issue.
Please "Accept the answer" if the information helped you. This will help us and others in the community as well.