These are NOT in any .htaccess files on my server:
# HTTP security settings start
Header set Strict-Transport-Security: max-age=2592000; includeSubDomains;
Header set X-Frame-Options: SAMEORIGIN
Header set Referrer-Policy: no-referrer-when-downgrade
Header set X-XSS-Protection: “1; mode=block”
Header set X-Content-Type-Options: nosniff
# HTTP security settings end