I've always wondered if I should apply any of the measures. I use Wordfence so thought it was redundant. Does anyone use them? They include options like blocking unauthorized access to xmlrpc.php and .htaccess.
There are many plugins and WordPress Managers offering same set of Security features.
Sometimes you need to install multiple plugins which offer individual settings and configure them all.
Further when you have multiple websites to manage you can use the WordPress Manager Security Settings to apply these settings on all sites at once by one click against configuring settings by logging into each sites.
You can use any method to secure the site as per your choice. The end goal should be that the sites are secured.