A system administrator is hardening a new FreeBSD server that will host critical financial data. A primary requirement is to prevent any modifications to kernel modules at runtime, even by the root user, once the system is fully booted. Which configuration in `/etc/sysctl.conf` will achieve this specific security objective?