I gave 500 & 400 as examples of what's possible, not necessarily what's easiest. There's no need for execute permission on files, for instance, and no user but your web server user (e.g. "apache", "www", etc.) needs to be able to read them for your site to work.
Clearly if you set your...