You can also deny access to file extensions using RedirectMatch directive :
RedirectMatch 403 ^/.+\.(php|html|gif)$
This will return a 403 forbidden error for clients if they request any uri that ends with .php or .html or .gif . You can add more extensions to the pattern using a bar | .