Apache allows access to everything inside the Document Root folder by default. This means directory and its all the subdirectories and their contents can be listed and accessed. However, you can use .htaccess to harden the security of your Server, and to
Read More How to Deny Access to Directory and Subdirectories using htaccess Ubuntu