KPMG interview question

They asked mainly about web application security pentesting.