Suspicious IP Throttling for Access Token Request

Do the Suspicious IP throttling settings also apply to the brute force or suspicious call to /oauth/token for access token request for Client credential grants?

If not, how can we throttle suspicious attempts for access token requests?