{"id":21506,"date":"2026-09-25T05:35:54","date_gmt":"2026-09-25T05:35:54","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=21506"},"modified":"2026-09-25T05:35:54","modified_gmt":"2026-09-25T05:35:54","slug":"splunk-splk-5001-practice-test-questions-and-exam-dumps-part4-q61-80","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/splunk-splk-5001-practice-test-questions-and-exam-dumps-part4-q61-80\/","title":{"rendered":"Splunk SPLK-5001 Practice Test Questions and Exam Dumps Part4 Q61-80"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/splk-5001-exam-dumps\"><b>Splunk SPLK-5001 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Question 61. What starts a hypothesis hunt?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Closing all alerts<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A testable security assumption<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Deleting old data<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Creating user accounts<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. A testable security assumption<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A hypothesis-driven threat hunt begins with a clear, testable idea about potentially malicious behavior. For example, an analyst might hypothesize that compromised accounts are using administrative tools outside normal working hours. The analyst then identifies relevant data sources, builds searches, reviews results, and refines the hypothesis based on evidence. Unlike purely alert-driven investigation, hunting proactively looks for threats that may not have triggered an existing detection. The SPLK-5001 blueprint specifically includes hypothesis hunting as an expected threat-hunting skill.<\/span><\/p>\n<p><b>Question 62. What is long-tail analysis used for?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Password resets<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data deletion<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Dashboard ownership<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Finding rare values or behaviors<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Finding rare values or behaviors<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Long-tail analysis focuses on uncommon values or behaviors that occur infrequently compared with normal activity. Rare command lines, unusual domains, uncommon processes, or rarely used accounts can be useful hunting leads because attackers often produce behavior that stands out from established patterns. Analysts should still validate context because rare does not automatically mean malicious. The SPLK-5001 blueprint specifically lists long-tail analysis as a threat-hunting concept candidates should understand.<\/span><\/p>\n<p><b>Question 63. What is an outlier?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A value far from normal behavior<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A scheduled report<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A lookup table<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A user role<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. A value far from normal behavior<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An outlier is an observation that differs significantly from the expected pattern of a dataset. In security analytics, examples can include a user downloading far more data than peers, a host contacting an unusually large number of destinations, or a login occurring from an unexpected location. Outliers are useful hunting leads but are not automatically malicious. Analysts must compare them with business context and other evidence before deciding whether an investigation or escalation is necessary. Outlier detection is explicitly included in the SPLK-5001 threat-hunting objectives.<\/span><\/p>\n<p><b>Question 64. What is a baseline?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A malware hash<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A firewall rule<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Expected normal behavior<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> An index name<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Expected normal behavior<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A baseline describes what normal activity looks like for an entity, system, network, or business process. Analysts can compare current activity with this baseline to identify meaningful deviations. For example, a user who normally logs in from one region during business hours may stand out if the account suddenly authenticates from several countries overnight. Baselines should evolve as legitimate behavior changes. They support anomaly detection and behavioral threat hunting because they provide the reference needed to distinguish common activity from unusual activity.<\/span><\/p>\n<p><b>Question 65. What does indicator hunting use?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Known suspicious artifacts<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only user interviews<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Firmware versions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Dashboard colors<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Known suspicious artifacts<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Indicator-based hunting searches for known artifacts associated with threats, such as malicious IP addresses, domains, file hashes, filenames, or URLs. Analysts can use threat intelligence to identify these indicators and then search historical Splunk data to determine whether the organization has encountered them. Indicator hunting is useful for quickly checking exposure to known threats, but it can miss attackers who change infrastructure or tools. Splunk&#8217;s blueprint lists indicators as one of the threat-hunting techniques analysts should understand.<\/span><\/p>\n<p><b>Question 66. What does behavioral hunting focus on?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Software licensing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> User account creation only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Static IP lists only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Suspicious actions and patterns<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Suspicious actions and patterns<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Behavioral hunting looks for attacker actions rather than relying only on known indicators. Examples include credential dumping, unusual process execution, lateral movement, or suspicious use of administrative tools. Because behaviors may remain similar even when attackers change domains, IP addresses, or file hashes, behavioral analytics can detect activity that simple indicator matching misses. Splunk&#8217;s SPLK-5001 blueprint identifies behavioral analytics as an important threat-hunting technique.<\/span><\/p>\n<p><b>Question 67. What does configuration hunting review?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Password age only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Risky or abnormal settings<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Email subjects only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS responses only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Risky or abnormal settings<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Configuration-based hunting looks for insecure, unusual, or unauthorized settings that may create attack opportunities or indicate compromise. Examples include disabled logging, newly created administrative permissions, weakened security controls, exposed services, or suspicious policy changes. Configuration hunting is particularly useful because attackers often alter settings to establish persistence or avoid detection. The SPLK-5001 blueprint includes configuration as a specific threat-hunting technique analysts should recognize.<\/span><\/p>\n<p><b>Question 68. What should follow hunt data collection?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Immediate closure<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data deletion<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Analysis of evidence<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> License renewal<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Analysis of evidence<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">After gathering data for a threat hunt, analysts examine the results for patterns that support or reject the original hypothesis. They may summarize events, compare entities, review timelines, investigate anomalies, and pivot into additional data sources. If the evidence does not support the hypothesis, the hunt can still provide useful information and lead to a refined question. Threat hunting is iterative rather than a one-step search. The analyst repeatedly uses evidence to narrow, adjust, or expand the investigation.<\/span><\/p>\n<p><b>Question 69. What does MITRE ATT&amp;CK organize?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> User passwords<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Index retention<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> License usage<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Adversary tactics and techniques<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Adversary tactics and techniques<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">MITRE ATT&amp;CK organizes observed adversary behavior into tactics and techniques. Tactics represent high-level objectives such as privilege escalation or command and control, while techniques describe specific methods used to achieve those objectives. Splunk Enterprise Security can associate risk events and detections with ATT&amp;CK tactics and techniques, giving analysts additional context during investigations. Splunk also uses ATT&amp;CK mappings in risk-based alerting to highlight combinations of behaviors associated with the same entity.<\/span><\/p>\n<p><b>Question 70. What does a risk factor do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Modifies a risk score<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Deletes risk events<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Creates indexes<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disables detections<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Modifies a risk score<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A risk factor adjusts the risk associated with an entity when additional context makes that entity more or less important. For example, activity involving a privileged administrator or high-value server may deserve a higher effective risk score than the same behavior involving a low-impact test account. Splunk&#8217;s risk-based alerting tutorial specifically includes using risk factors to raise risk scores for watchlisted users. Risk factors help incorporate business context into the scoring process rather than treating every entity identically.<\/span><\/p>\n<p><b>Question 71. What does RBA combine?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Multiple risk events<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only raw packets<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only one alert<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only DNS records<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Multiple risk events<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk-based alerting combines multiple lower-level risk events associated with the same user, system, or other entity. Individually, each event may not justify immediate analyst attention, but together they can form a stronger security story. Splunk explains that RBA can aggregate activity over time, across data sources, and across MITRE ATT&amp;CK techniques before creating a higher-confidence risk notable or finding. This reduces reliance on isolated point-in-time alerts and can expose complex attack behavior.<\/span><\/p>\n<p><b>Question 72. What does a risk threshold trigger?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data deletion<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Password reset<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Higher-priority investigation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Index rotation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Higher-priority investigation<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A risk threshold defines when accumulated risk becomes significant enough to generate a risk notable, finding, or other investigation-worthy result. Splunk&#8217;s documentation gives examples in which several risk events combine until their total score crosses a defined threshold. Thresholds should be tuned to the environment because values that are too low can create excessive alert volume, while values that are too high can delay detection. Analysts can also consider MITRE tactic count, confidence, and other criteria when tuning RBA.<\/span><\/p>\n<p><b>Question 73. What does RBA reduce?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disk capacity<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Low-fidelity alert noise<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data sources<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Authentication logs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Low-fidelity alert noise<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">One major goal of risk-based alerting is to reduce the number of isolated low-value alerts analysts must review. Instead of creating a separate urgent alert for every suspicious action, RBA can accumulate risk and generate a higher-fidelity story when activity becomes significant. This helps analysts spend more time on meaningful investigations and threat hunting. Splunk describes RBA as a way to correlate related activity, streamline investigations, and reduce alert volume while improving context.<\/span><\/p>\n<p><b>Question 74. What can an adaptive response action do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Take an automated security action<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Rename indexes only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Change dashboards only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Delete all raw events<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Take an automated security action<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Adaptive response actions allow Splunk Enterprise Security to perform or trigger response activities based on detection or investigation results. Depending on integrations and permissions, actions can enrich an event, update risk, initiate containment, create tickets, or interact with external security tools. The SPLK-5001 blueprint specifically expects candidates to determine when adaptive response actions should be used and understand how they are configured. Analysts should apply automation carefully because response actions can affect production systems.<\/span><\/p>\n<p><b>Question 75. What is SOAR mainly used for?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Orchestrating security workflows<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Storing raw Splunk indexes<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Creating DNS zones<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Configuring operating systems<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Orchestrating security workflows<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security orchestration, automation, and response platforms coordinate repeatable security workflows across multiple tools. A SOAR playbook can gather enrichment, query external systems, request analyst approval, create tickets, block indicators, disable accounts, or perform other supported actions. The SPLK-5001 blueprint specifically requires candidates to understand the use of SOAR playbooks and the basic ways they can be triggered from Enterprise Security. Playbooks are most valuable for repeatable processes where automation reduces analyst effort and response time.<\/span><\/p>\n<p><b>Question 76. What is a SOAR playbook?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A threat feed<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A saved dashboard<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Automated response workflow<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A data model<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Automated response workflow<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A SOAR playbook is a defined sequence of automated or semi-automated actions used to investigate or respond to security events. A playbook might enrich an IP address, check reputation services, query endpoint data, ask for analyst approval, and then isolate a host if necessary. Playbooks improve consistency because the same response process can be followed every time a similar event occurs. They can also reduce response time by automating repetitive tasks that would otherwise require manual analyst effort. The SPLK-5001 blueprint explicitly includes SOAR playbooks under threat hunting and remediation.<\/span><\/p>\n<p><b>Question 77. What can trigger a detection action?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A matched detection pattern<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A monitor color<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> An index name only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A dashboard title<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. A matched detection pattern<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Detections search one or more data sources for patterns that may indicate suspicious activity. When the search conditions are met, Splunk Enterprise Security can take configured actions such as creating a finding, adjusting a risk score, or performing an adaptive response action. Modern Splunk documentation describes detections as central to the investigation lifecycle because they turn matched analytical logic into actionable security findings. The action depends on how the detection is configured.<\/span><\/p>\n<p><b>Question 78. Why map detections to ATT&amp;CK?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Increase storage<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Add adversary context<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reduce timestamps<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Rename indexes<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Add adversary context<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Mapping detections to MITRE ATT&amp;CK helps analysts understand which adversary tactics and techniques are represented by observed behavior. This improves investigation context and lets security teams visualize detection coverage across the ATT&amp;CK matrix. Splunk&#8217;s RBA documentation specifically describes using ATT&amp;CK mappings to build situational awareness around users and systems and identify security gaps. ATT&amp;CK context can also help analysts connect several apparently separate events into one broader attack sequence.<\/span><\/p>\n<p><b>Question 79. What does hunt refinement improve?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Search focus<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> License expiration<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Index ownership<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Password length<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Search focus<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Threat hunting is iterative. An analyst may start with a broad hypothesis and then refine the search as evidence reveals which users, hosts, times, or behaviors matter most. Refinement reduces irrelevant results and makes the hunt more precise. A hunt that finds nothing can still be useful because it may reveal that the hypothesis was too broad or that a required data source is missing. Analysts should document these findings and use them to improve future hunts and detection content.<\/span><\/p>\n<p><b>Question 80. What is the goal of threat hunting?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Delete old alerts<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Replace all detections<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Proactively find hidden threats<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable automation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Proactively find hidden threats<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Threat hunting proactively searches for malicious or suspicious behavior that may not have triggered existing alerts. Hunters use hypotheses, behavioral analytics, anomaly detection, indicators, configuration review, long-tail analysis, and contextual data to identify possible threats. Findings from hunts can also improve future detections and response processes. The SPLK-5001 blueprint dedicates a specific section to threat hunting and remediation, including hunting techniques, hypothesis hunting, adaptive response, and SOAR playbooks.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Splunk SPLK-5001 Exam Dumps and Practice Test Dumps. Question 61. What starts a hypothesis hunt? Closing all alerts A testable security assumption Deleting old data Creating user accounts Correct Answer: 2. A testable security assumption Explanation: A hypothesis-driven threat hunt begins with a clear, testable idea about potentially malicious behavior. For example, an [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21506"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=21506"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21506\/revisions"}],"predecessor-version":[{"id":21507,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21506\/revisions\/21507"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=21506"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=21506"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=21506"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}