Replacing public-key exchange with physically distributed pre-shared symmetric keys is very secure and efficient once set up but scales poorly and rules out certificate validation, so the hybrid approach is recommended unless a system meets all six conditions: it has to move in the most urgent scenario; it is fully controlled and completely trusted; it communicates only with equally trusted and controlled systems; keys can practically be shared between the systems; the networks involved are highly confidential with a layout that seldom changes; and nodes are rarely added or removed. TLS and IPsec are examples where this is possible.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.