Easily “guessable” file or application structures lead to possible compromises. For example, placing your admin section in an /admin/ directory (URI) makes your application an easier target for CGI or directory scanning.