If you want to protect and most secure your server should be disabled your Linux server Root Access. Hacker can't hack your server.
I think this video very helpful for Linux System Admin.
#DisableRootUserFromSSHCentos
#CreateAdminUserInCentosRedhat
#DisableRootAccessLinuxCenotsRedHat
#DisableTheSSHRootLogin
#DeactivatingTheSSHRootLogin
#HowtoDisableSSHRootLogininLinux
#DisableSSHloginsForTheRootAccount
#DisableOrEnableSSHRootLoginAndLimitSSHAccess