👉 Example:

Content-Security-Policy: default-src 'self'; script-src 'self' <https://cdn.example.com>

✅ Prevents:

⚠️ Weak CSP (e.g., unsafe-inline) → makes CSP useless.

Pentesting Focus