| Q251 | HTTP boundary | Read methods, status, headers, body, credentials, cache policy, and security headers before blaming UI state. |
| Q252 | Caching | Classify responses by freshness, sensitivity, invalidation path, and whether browser or shared caches may store them. |
| Q253 | Lifecycle | Separate DNS, TCP, TLS, TTFB, transfer, parsing, and rendering when debugging performance. |
| Q254-Q255 | Origin and trust | CORS controls browser read access; browser security depends on explicit origins, storage rules, CSP, and sandbox boundaries. |