WebPageTest.org Header Fixing Security

Header set Strict-Transport-Security "max-age=31536000; includeSubDomains" "expr=%{HTTPS} == 'on'"
Header set Content-Security-Policy "default-src 'self';"
Header set X-Content-Type-Options nosniff
Header always append X-Frame-Options DENY
<IfModule mod_headers.c>
  Header set X-XSS-Protection "1; mode=block"
</IfModule>
Alaminislam05