I hope 100% of the respondents answer that they've used "Content-Security Policy (CSP)" as it's there by default and by answering anything else, they probably out themselves as basically not knowing their own space where they work.
There are a lot of ways you could send a valid response without including that header or tag, any policies are not one-size-fits all and could be different. Maybe you’re using a full-stack framework which is managing it for you?
Or maybe you’re confusing it with CORS?
So if you haven't done anything to work with something can you say you've 'used' it.
Perhaps people just demonstrate a different opinion of linguistic usage?