{"id":21509,"date":"2026-09-25T05:52:18","date_gmt":"2026-09-25T05:52:18","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=21509"},"modified":"2026-09-25T05:52:18","modified_gmt":"2026-09-25T05:52:18","slug":"splunk-splk-5001-practice-test-questions-and-exam-dumps-part5-q81-100","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/splunk-splk-5001-practice-test-questions-and-exam-dumps-part5-q81-100\/","title":{"rendered":"Splunk SPLK-5001 Practice Test Questions and Exam Dumps Part5 Q81-100"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/splk-5001-exam-dumps\"><b>Splunk SPLK-5001 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Question 81. What is a correlation search?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Raw event storage<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Dashboard formatting<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Security search with response actions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Index retention rule<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Security search with response actions<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A correlation search is a saved security search with additional capabilities for detecting defined patterns in one or more data sources. When its conditions are satisfied, it can create a notable event or finding, modify a risk score, or launch an adaptive response action. Analysts use correlation searches to automate detection of suspicious behavior rather than manually running the same SPL repeatedly. Splunk recommends testing the underlying search logic before enabling it in production so the detection produces useful results without excessive noise.<\/span><\/p>\n<p><b>Question 82. What can a correlation search create?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Notable event<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> New indexer<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> User password<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data retention policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Notable event<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A correlation search can generate a notable event when its search logic matches suspicious activity. It can also modify risk or perform an adaptive response action, depending on how the search is configured. Notable events provide analysts with structured findings that can be reviewed and triaged rather than requiring them to monitor every raw event manually. Correlation searches are therefore a bridge between SPL-based detection logic and the analyst investigation workflow in Splunk Enterprise Security.<\/span><\/p>\n<p><b>Question 83. Why schedule a correlation search?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Delete old data<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable SPL<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Change index names<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Run detection logic automatically**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Run detection logic automatically<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Scheduling allows a correlation search to run automatically at defined intervals instead of relying on an analyst to execute it manually. This provides continual monitoring for patterns such as repeated failed logins, suspicious process behavior, or unusual network activity. The search time range and schedule should be aligned carefully so important events are not missed or repeatedly processed. Splunk&#8217;s correlation-search workflow includes planning the use case, creating the search, defining its schedule, and selecting the appropriate response actions.<\/span><\/p>\n<p><b>Question 84. What does correlation-search throttling reduce?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data-model size<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Repeated response actions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Raw event count<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Indexer storage<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Repeated response actions<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Throttling limits how often a correlation search generates response actions for matching activity. This is useful when one condition could otherwise create many nearly identical findings or actions over a short period. Splunk distinguishes throttling from notable suppression: throttling prevents excessive response actions from being generated, while suppression hides matching notable events from the Incident Review view after those events have already been created. Correct throttling can reduce analyst noise while preserving useful detection coverage.<\/span><\/p>\n<p><b>Question 85. What does notable suppression do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Deletes raw events<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Stops indexing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disables all detections<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Hides matching notables from Incident Review**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Hides matching notables from Incident Review<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Notable suppression uses a search filter to hide selected notable events from the Incident Review dashboard. Splunk documentation emphasizes that the suppressed events are still created and remain in the notable index; they are simply hidden from the normal review view. They can also continue to contribute to counts on other dashboards. Suppression is useful when known benign or repetitive findings would otherwise distract analysts, but it should be applied carefully so important activity is not hidden unintentionally.<\/span><\/p>\n<p><b>Question 86. What does data-model acceleration improve?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Search performance<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Password strength<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Alert ownership<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> License count<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Search performance<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data-model acceleration builds summary information that can be queried much faster than repeatedly searching all underlying raw events. Splunk Enterprise Security uses accelerated data models to populate dashboards, support views, and provide detection or correlation-search results. Acceleration improves performance especially when data models represent very large datasets, but it also consumes processing and storage resources on indexers. Administrators therefore need to choose acceleration settings and summary ranges that balance search performance with infrastructure capacity.<\/span><\/p>\n<p><b>Question 87. Where are acceleration summaries stored?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Browser cache<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Indexer storage<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> User profile<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Lookup editor only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Indexer storage<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data-model acceleration summaries are created and stored on the indexer tier. Splunk describes the accelerated summaries as being saved alongside the source index buckets and built from TSIDX-based information. Searches that use accelerated data can then query these summaries rather than repeatedly processing the entire underlying raw dataset. Because acceleration requires additional indexer processing and disk space, administrators should consider retention, index constraints, and infrastructure capacity when enabling or tuning it.<\/span><\/p>\n<p><b>Question 88. What does <\/b><b>tstats<\/b><b> query efficiently?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Dashboard colors<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> User passwords<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Indexed fields and data models<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> License files<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Indexed fields and data models<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">tstats<\/span><span style=\"font-weight: 400;\"> command performs statistical searches over indexed fields stored in TSIDX files and can query indexed data or data models. Because it works with indexed field information rather than scanning raw events in the same way as many ordinary searches, <\/span><span style=\"font-weight: 400;\">tstats<\/span><span style=\"font-weight: 400;\"> is generally faster than <\/span><span style=\"font-weight: 400;\">stats<\/span><span style=\"font-weight: 400;\"> for supported use cases. It is commonly used with accelerated CIM data models in security searches to produce efficient counts, values, and grouped results across large datasets.<\/span><\/p>\n<p><b>Question 89. Why is <\/b><b>tstats<\/b><b> often faster than <\/b><b>stats<\/b><b>?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It uses indexed TSIDX data<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It disables fields<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It skips authentication<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> It searches only dashboards<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. It uses indexed TSIDX data<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">tstats<\/span><span style=\"font-weight: 400;\"> performs statistical queries using indexed fields stored in TSIDX structures. This means it can avoid repeatedly reading and interpreting full raw events for supported searches. Splunk explicitly notes that <\/span><span style=\"font-weight: 400;\">tstats<\/span><span style=\"font-weight: 400;\"> is faster than <\/span><span style=\"font-weight: 400;\">stats<\/span><span style=\"font-weight: 400;\"> because it searches index-time fields rather than raw events. When combined with accelerated data models, this performance advantage makes <\/span><span style=\"font-weight: 400;\">tstats<\/span><span style=\"font-weight: 400;\"> particularly useful for large-scale security dashboards, detections, and analytical searches.<\/span><\/p>\n<p><b>Question 90. What does <\/b><b>FROM datamodel=<\/b><b> specify?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Dashboard owner<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Risk score<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> User role<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data model to query<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Data model to query<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">In a <\/span><span style=\"font-weight: 400;\">tstats<\/span><span style=\"font-weight: 400;\"> search, the <\/span><span style=\"font-weight: 400;\">FROM datamodel=<\/span><span style=\"font-weight: 400;\"> clause identifies the data model and dataset that provide the search data. This lets analysts query normalized fields from models such as Authentication, Network Traffic, or other CIM-aligned datasets rather than directly referencing vendor-specific raw sources. Using data models can make detection logic more portable across different technologies as long as the underlying data is correctly normalized to the Common Information Model.<\/span><\/p>\n<p><b>Question 91. What does <\/b><b>summariesonly=true<\/b><b> favor?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Raw-event scanning<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Acceleration summaries<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Lookup editing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Dashboard XML<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Acceleration summaries<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">summariesonly=true<\/span><span style=\"font-weight: 400;\"> option instructs <\/span><span style=\"font-weight: 400;\">tstats<\/span><span style=\"font-weight: 400;\"> to rely on available data-model acceleration summaries rather than combining summarized and unsummarized data. This can provide fast and predictable performance when the required time range is fully covered by the acceleration summaries. Analysts should understand the acceleration summary range because data outside that range may not be represented when <\/span><span style=\"font-weight: 400;\">summariesonly=true<\/span><span style=\"font-weight: 400;\"> is used. Splunk Enterprise Security frequently uses accelerated models for high-performance analytical searches.<\/span><\/p>\n<p><b>Question 92. What does a data model provide?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Normalized structured datasets<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Firewall firmware<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> User passwords<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Index replication only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Normalized structured datasets<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A data model organizes related fields and events into structured datasets that analysts and applications can query consistently. In Splunk Enterprise Security, many data models come from the Common Information Model and represent security concepts such as authentication, endpoint activity, or network traffic. Data models help separate detection logic from vendor-specific raw field names. When the underlying events are correctly mapped to CIM, multiple technologies can contribute to the same normalized dataset and support common dashboards and detections.<\/span><\/p>\n<p><b>Question 93. What does CIM acceleration support?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Faster dashboards and searches<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Stronger passwords<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Email delivery<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> License renewal<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Faster dashboards and searches<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Accelerating CIM data models creates summary data that reports and dashboard panels can query more quickly. Splunk documentation specifically notes that accelerating a data model improves the response time of reports and dashboards that reference that model. Splunk Enterprise Security also enforces acceleration for selected models because many security dashboards and detections depend on fast access to normalized data. The benefit comes with additional indexer processing and storage requirements, so acceleration settings should be managed intentionally.<\/span><\/p>\n<p><b>Question 94. What helps prioritize a notable?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Urgency<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Index name<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> SPL length<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Dashboard theme<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Urgency<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Urgency is used to help analysts prioritize notable events or findings for investigation. Splunk Enterprise Security supports urgency categories such as critical, high, medium, low, informational, and unknown. Analysts can filter Incident Review by urgency to focus attention on the most important findings first. In classic notable-event handling, urgency is influenced by factors such as the detection severity and the priority associated with the relevant asset or identity.<\/span><\/p>\n<p><b>Question 95. What can affect notable urgency?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Browser version<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Severity and asset priority<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Search-head color<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Index bucket size<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Severity and asset priority<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Splunk Enterprise Security calculates notable urgency using contextual information, including the severity associated with the correlation search and the priority of the affected asset or identity. This means the same detection can be treated as more urgent when it affects a high-value system or user. Contextual prioritization helps analysts focus on findings with greater potential business impact rather than treating every detection result identically.<\/span><\/p>\n<p><b>Question 96. What does Incident Review status track?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Case progress<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data-model storage<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Index replication<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Search acceleration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Case progress<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Incident Review status reflects where a notable event stands in the investigation workflow. Splunk documents statuses such as New, In-progress, Pending, Resolved, and Closed. Analysts can filter findings by status and update them as work progresses. This helps SOC teams coordinate ownership and avoid duplicated effort, especially when many analysts work from the same queue. Status describes investigation progress and is separate from urgency, which reflects importance or priority.<\/span><\/p>\n<p><b>Question 97. What does the Owner field identify?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Assigned analyst<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data source<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Search index<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Risk threshold<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Assigned analyst<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Owner field identifies the person assigned to work on a notable event or investigation item. Incident Review can be filtered by owner so analysts can quickly see their assigned work or supervisors can understand workload distribution. Assigning ownership improves accountability and helps prevent several analysts from independently investigating the same finding without coordination. Ownership is separate from the status of the notable and from its urgency or security domain.<\/span><\/p>\n<p><b>Question 98. What does Security Domain classify?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Password strength<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Detection category<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> User session length<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Index size<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Detection category<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security Domain classifies findings according to broad security categories. Splunk documents examples including Access, Endpoint, Network, Threat, Identity, and Audit. Analysts can use this classification to filter Incident Review or understand what type of security problem generated the finding. Security domains also support dashboard summarization, allowing security teams to see whether current detections are concentrated in areas such as identity or endpoint activity.<\/span><\/p>\n<p><b>Question 99. What does suppression NOT do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Hide selected notables<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reduce dashboard noise<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Prevent event creation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Filter Incident Review<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Prevent event creation<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A notable suppression does not stop matching notable events from being created. Splunk explicitly states that suppressed notables are still generated and stored in the notable index; suppression simply hides them from the Incident Review dashboard. If the goal is to prevent repeated response actions or findings from being generated in the first place, correlation-search throttling is the more appropriate control. Understanding this distinction is important when tuning noisy detection content.<\/span><\/p>\n<p><b>Question 100. What BEST improves ES search speed?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Accelerated data models with <\/span><span style=\"font-weight: 400;\">tstats<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> More raw-event scans<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Removing CIM<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disabling summaries<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Accelerated data models with <\/b><b>tstats<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Accelerated data models and <\/span><span style=\"font-weight: 400;\">tstats<\/span><span style=\"font-weight: 400;\"> are designed for high-performance searches over structured security data. Data-model acceleration creates TSIDX-based summaries, while <\/span><span style=\"font-weight: 400;\">tstats<\/span><span style=\"font-weight: 400;\"> can query indexed fields and those accelerated datasets efficiently. Splunk Enterprise Security relies on this architecture to populate dashboards and support detection results without repeatedly scanning large volumes of raw events. Proper CIM normalization, acceleration settings, and index constraints therefore contribute directly to both search consistency and performance.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Splunk SPLK-5001 Exam Dumps and Practice Test Dumps. Question 81. What is a correlation search? Raw event storage Dashboard formatting Security search with response actions Index retention rule Correct Answer: 3. Security search with response actions Explanation: A correlation search is a saved security search with additional capabilities for detecting defined patterns in [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21509"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=21509"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21509\/revisions"}],"predecessor-version":[{"id":21510,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21509\/revisions\/21510"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=21509"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=21509"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=21509"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}