-what is nmap
-what is xss and its types
-what is blind xss and blind sql injection
-what is csrf and how to mitigate it
-explain host header injection and different techniques to successfully exploit it
-how many types of attacks in burp suite intruder
-have you used any vulnerability scanners
-explain session hijacking
-perform authentication bypass
-why is dns used for
-name different protocols that run on application layer