An IIS admin is asked to implement content security policy headers to prevent XSS attacks. Where should these headers be added?
-
A
In the DNS configuration for the domain
-
B
As HTTP response headers in IIS Manager or web.config <customHeaders>
-
C
In the SSL certificate metadata
-
D
Via the application pool environment variables