That's what it is for, but most setups don't have it setup correct (the verification page should ONLY appear during an actual DDoS, and even then only against IPs that appear to be participating).
It wants to do a bit of cryptography, which means that if scripts/WASM/etc are disabled, you can be out of luck.