I got laid off last month and elbow deep in the onsite portion of interview process. It's wild to me that every onsite (3/3 now) asked for an explanation of SOP and CORS.
also, how wildly different the skillsets are for each position in 'application security'