Yes, it's more secure outside that folder because even if there is a vulnerability in the IIS, the chances of hackers being able to exploit it are lower, since they get there through the browser.