What it is
Checks the response headers that harden a site against browser-side attacks. HSTS forces HTTPS. Content-Security-Policy restricts where scripts, styles and other resources may load from, and is the main defence against cross-site scripting. X-Content-Type-Options stops browsers second-guessing a declared content type. X-Frame-Options controls whether the page can be embedded in a frame, which is what prevents clickjacking.
Why it matters
These cost nothing to add and are very often simply absent. A site missing all of them is not necessarily exploitable, but it has opted out of several protections the browser would otherwise enforce on its behalf. Being present is not enough either, since a CSP that allows inline scripts stops very little.