Which of the following HTTP headers is crucial for preventing Cross-site Scripting (XSS) attacks?

  • Content-Encoding
  • Access-Control-Allow-Origin
  • X-Frame-Options
  • User-Agent
The HTTP header crucial for preventing Cross-site Scripting (XSS) attacks is X-Frame-Options. This header prevents a web page from being embedded within an