HTTP/2 200 content-type: text/html; charset=utf-8 content-length: 7012 content-encoding: gzip pragma: no-cache content-security-policy: object-src 'none'; frame-ancestors 'self' https://*.federalreserveeducation.org https://*.instructure.com https://*.d2l.com https://*.brightspace.com https://*.schoology.com https://*.powerschool.com https://*.blackboard.com https://*.anthology.com https://*.frb.org https://*.edu; upgrade-insecure-requests; block-all-mixed-content cross-origin-resource-policy: same-origin permissions-policy: accelerometer=(), autoplay=(), camera=(), cross-origin-isolated=(), display-capture=(), fullscreen=(), geolocation=(), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), payment=(), publickey-credentials-get=(), screen-wake-lock=(), sync-xhr=(self), usb=(), web-share=(), xr-spatial-tracking=(), gamepad=(), hid=(), idle-detection=(), interest-cohort=(), serial=() x-content-type-options: nosniff x-permitted-cross-domain-policies: none referrer-policy: strict-origin-when-cross-origin accept-ch: Sec-CH-UA-Full-Version-List,Sec-CH-UA-Platform-Version,Sec-CH-UA-Arch,Sec-CH-UA-Model,Sec-CH-UA-Bitness request-context: appId=cid-v1:fb3396d3-cfcc-4750-8da7-854916273bb3 x-powered-by: ASP.NET cache-control: no-cache, no-store expires: Sun, 19 Jul 2026 08:47:05 GMT date: Sun, 19 Jul 2026 08:47:05 GMT vary: Accept-Encoding alt-svc: h3=":443"; ma=93600 strict-transport-security: max-age=86400 x-frame-options: SAMEORIGIN