如果你個website係static (全html, 冇server side programming), 或者有server side programming 但冇需要做upload 或者 冇做file based cached, 咁全部root:root 755 (dir), 644(file) 係一個唔錯既選擇.
因為冇乜必要比apache權限去寫file or create folder. 咁做就冇咁易被compromised.
如果係你需要做upload, or server side programming需要create files or dirs,
咁你就只需要將upload folder chown 做www-data, 佢就可以create files or dirs.
如果可以用htaccess 你就加埋upload folder cast .php 做text/plain