My vulnerability reports says X-Content-Type-Options is missing from my HTTP headers. How do I add a security header for HTTP?

Go to the HTTP/HTTPS advanced setting and open the custom headers dialog box. You can add a new header. 

In this case, add a header called "X-Content-Type-Options" and set its value to "nosniff".