DeepFrontend
Learning Paths
Practice
System Design & DS
Design Studio
Data Structures Curriculum
Real-World Case Studies
Careers
Job Board
Resume Builder
Blog
Sign in
Search
⌘K
Go Pro
Loading compiler resources...
Web Security Quiz Practice
Active Recall Drill Session
← Exit Session
Question 1 of 1
medium
Web Security
What's the purpose of deploying Content-Security-Policy-Report-Only before switching to full enforcement?
A
It has no real purpose, just an alternate header name
B
It lets a team observe real violations from real production traffic and tune the policy before it actually starts blocking anything
C
It's required by browsers before any enforcing policy can be set
D
It only works in development environments
Check Answer