Lazo Lab Sign up

Web Security / Building secure apps

Lesson 20 of 27

Security headers

Headers like Strict-Transport-Security, X-Content-Type-Options and X-Frame-Options switch on browser protections with one line each.

Key points

  • HSTS forces HTTPS
  • nosniff stops content-type guessing
  • frame-ancestors stops clickjacking
Watch a video on thisOpens YouTube search results for “Security headers” in a new tab

Quiz · +10 XP

Which header forces browsers to always use HTTPS?

Log in to save progress and earn XP.