Securing WordPress Against Hackers and DDoS Attacks

You can also put your wp-config.php file one step above its root directory. It will be accessible to WordPress itself but not to others unless WordPress is installed in some sub-directory.