All the "Game IPS" services are opt in (off by default). I can only speculate as to the reason for this decision, but it can be unsettling seeing some of the false positives that come from these services. For example, if you need "inside the firewall" uPnP, the router security assessment will show this as a risk. This isn't an example of a false positive, but turning off uPnP "inside the firewall" can cause more network problems than the risk it mitigates (ok, please, I'm not trying to debate this and I agree that uPnP is a significant risk if your home network is compromised). But another example is "Malicious Sites Blocking" feature. I've had to turn this feature off in order to ensure that I can get to quite a few "unsubscribe" websites from internet based marketing companies. I get no other telemetry saying that the "unsubscribe" site is malicious (although since I receive most of this spam unsolicited, I can see how the domains might be considered malicious, neither Chrome nor Edge mark the sites as malicious.
I don't think I've been a target for a DDoS attack, but I can tell you that I leave both "Two-Way IPS" and "Infected Device Prevention and Blocking" on with no noticeable impact on router CPU. But this router has a monster of a CPU and I haven't seen anyone ever complain about the processor on this beast keeping up with demands (even from those routing symmetrical gigabit traffic).