NCC Group interview question

Talk about CSRF, XSS