With a single-server setup for simplicity, which steps could you do to minimize the attacks of a (D)DoS attack? And is it really worth it taking these steps, considering their effectivity and impact on 'normal' users?
[EDIT] I also meant to include steps which you would need inject into your code to apply, not only IIS setup.