{"id":21517,"date":"2026-09-25T05:53:31","date_gmt":"2026-09-25T05:53:31","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=21517"},"modified":"2026-09-25T05:53:31","modified_gmt":"2026-09-25T05:53:31","slug":"splunk-splk-5001-practice-test-questions-and-exam-dumps-part9-q161-180","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/splunk-splk-5001-practice-test-questions-and-exam-dumps-part9-q161-180\/","title":{"rendered":"Splunk SPLK-5001 Practice Test Questions and Exam Dumps Part9 Q161-180"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/splk-5001-exam-dumps\"><b>Splunk SPLK-5001 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Question 161. What is an entity in Enterprise Security?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A dashboard<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A lookup file<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A search command<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A subject of suspicious activity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. A subject of suspicious activity<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An entity represents a user, system, device, or other object associated with suspicious, anomalous, or malicious activity. Splunk Enterprise Security uses entities to help analysts understand which people or systems are affected by security findings. Entities can be normalized against known asset and identity information and can also carry risk information. This context helps analysts connect several findings that involve the same system or user instead of reviewing each detection independently. Splunk&#8217;s current Enterprise Security documentation identifies entities as central objects for understanding potential security threats.<\/span><\/p>\n<p><b>Question 162. What does an asset represent?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A user password<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A system or network resource<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A dashboard panel<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> An SPL command<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. A system or network resource<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An asset generally represents a system or network resource such as a server, workstation, network device, IP address, or other infrastructure component. Splunk can use asset information to add context such as ownership, location, criticality, and associated identities during an investigation. Asset context is useful because an alert involving a critical production server may deserve more attention than the same activity on a low-value test machine. Splunk Asset and Risk Intelligence can aggregate asset information from several data sources and associate it with IP addresses, MAC addresses, software, and vulnerabilities.<\/span><\/p>\n<p><b>Question 163. What does an identity represent?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A user or account<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A network packet<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A data model<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> An index bucket<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. A user or account<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An identity represents a person, account, or other user-related entity that can be associated with security activity. Identity context helps analysts understand who performed an action, which accounts belong to the same user, and whether a privileged or sensitive account is involved. Splunk can correlate identity information with authentication, endpoint, cloud, and network evidence. This makes it easier to investigate account takeover, privilege misuse, or suspicious login patterns. Asset and identity information together provide richer context than reviewing raw event fields without knowing who or what those fields represent.<\/span><\/p>\n<p><b>Question 164. What does the Assets and Identities framework provide?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Password rotation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data deletion<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Entity normalization and context<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Index replication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Entity normalization and context<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Assets and Identities framework helps Splunk Enterprise Security normalize information about known systems and users so detections and investigations can include meaningful context. An IP address can be associated with a hostname, criticality, owner, or other asset information, while usernames can be associated with identities and organizational information. This helps analysts prioritize findings and correlate activity involving the same underlying entity even when different data sources use different identifiers. Current Splunk documentation describes entities as being normalized against known assets and identities through this framework.<\/span><\/p>\n<p><b>Question 165. What does asset priority indicate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Business importance<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Search speed<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Index size<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Dashboard color<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Business importance<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Asset priority represents the relative importance of a system or resource to the organization. A critical production database, identity server, or payment system may receive a higher priority than a temporary test system. This context helps security tools and analysts distinguish between findings that have different potential business impacts. Splunk asset lookups include priority-related fields, and asset information can contribute to investigation and risk context. Accurate priority values help analysts focus first on findings involving systems where compromise would have the greatest operational or security consequences.<\/span><\/p>\n<p><b>Question 166. What is a threat list?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A user directory<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A data model<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A dashboard filter<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A collection of threat indicators<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. A collection of threat indicators<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A threat list contains indicators supplied by threat intelligence sources for use in matching and investigation enrichment. Indicators may include IP addresses, domains, URLs, file hashes, or other observables associated with malicious or suspicious activity. Splunk Enterprise Security can use several threat lists so security teams can organize intelligence by source, purpose, or tool. Matching local events against these indicators can reveal whether the organization has communicated with known malicious infrastructure or encountered known malicious files. Splunk&#8217;s current documentation defines threat lists as lists of threat indicators used for threat matching and enrichment.<\/span><\/p>\n<p><b>Question 167. What does threat matching do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Creates VLANs<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Compares events with threat indicators<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Deletes stale data<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Builds dashboards<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Compares events with threat indicators<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Threat matching compares local security data against known threat indicators from configured intelligence sources. For example, DNS events can be checked for malicious domains, proxy logs for dangerous URLs, or endpoint events for known file hashes. A match does not automatically prove compromise because indicators can become outdated or appear in legitimate contexts. Analysts should therefore review supporting evidence before reaching a conclusion. Splunk Enterprise Security uses threat intelligence sources and threat lists to support this type of matching and enrich investigations with additional context.<\/span><\/p>\n<p><b>Question 168. What is a safelist used for?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Increasing risk scores<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Creating detections<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Excluding known benign indicators<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Accelerating data models<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Excluding known benign indicators<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A safelist contains indicators or values known to be legitimate so they can be excluded from certain threat-intelligence matches or security workflows. For example, an organization&#8217;s own testing domain might appear in a threat feed because of research activity but should not generate repeated investigation noise. Safelisting helps reduce false positives when the security team has strong evidence that a particular value is trusted. Splunk Enterprise Security threat intelligence management supports safelist libraries as part of the workflow for managing cloud-hosted threat intelligence.<\/span><\/p>\n<p><b>Question 169. Where does the Threat Intelligence Framework reside?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> In a browser extension<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> In DNS<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> In the endpoint agent only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> In Splunk Enterprise Security<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. In Splunk Enterprise Security<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Splunk&#8217;s Threat Intelligence Framework is part of the Enterprise Security application. It can ingest intelligence from configured sources and aggregate that information into threat intelligence KV Store collections. This differs from Threat Intelligence Management Cloud, which is a cloud-hosted intelligence system. Both can support threat matching, but their configuration and storage models differ. Analysts should understand where the intelligence originates because investigation views and management workflows can differ between the native framework and cloud-based threat intelligence services.<\/span><\/p>\n<p><b>Question 170. What is an observable?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> An artifact such as an IP or hash<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A dashboard theme<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A user role<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> An index setting<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. An artifact such as an IP or hash<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An observable is a value that can be examined or enriched during an investigation, such as an IP address, domain, URL, file hash, or executable. Observables provide pivot points for threat intelligence and additional investigation. For example, an analyst can check whether an IP address has a malicious reputation or whether a file hash appears in known malware intelligence. Current Splunk threat intelligence integrations can enrich investigation observables including IP addresses, domains, URLs, and SHA-256 file hashes with external intelligence context.<\/span><\/p>\n<p><b>Question 171. What is an investigation?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A lookup table<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> An index<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A case built around security findings<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A field extraction<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. A case built around security findings<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An investigation is a structured case used to gather evidence, collaborate, and respond to a potential security incident. It is based on one or more findings and appears in the analyst queue in Mission Control. Analysts can add evidence, notes, response plans, automation results, and relevant entities while working the case. Investigations provide a broader workflow than simply reviewing a single finding because they allow related activity to be collected and analyzed together. Splunk describes investigations as collaborative processes for identifying, collecting, examining, and responding to security threats.<\/span><\/p>\n<p><b>Question 172. What is a finding?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Raw index data<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Security result generated by a detection<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A configuration file<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A lookup definition<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Security result generated by a detection<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A finding is a security result produced by detection logic. It contains information about what was observed, which entity was affected, and other context such as timestamps, risk values, or threat objects. A finding may or may not represent a genuine security incident, so analysts must triage it before deciding how to proceed. Related findings can be grouped together or added to an investigation for deeper analysis. Current Splunk Enterprise Security documentation describes findings as anomalous incidents or alerts created by event-based detections.<\/span><\/p>\n<p><b>Question 173. What is a response plan?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Standardized investigation tasks<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Threat feed<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data model<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Risk object<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Standardized investigation tasks<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A response plan is a template containing phases, tasks, and guidance that analysts follow while responding to an investigation. It helps standardize incident-handling procedures so different analysts respond consistently. Splunk Enterprise Security includes built-in response plans and also allows organizations to create custom plans based on their own standard operating procedures. Tasks can include searches, notes, files, actions, or playbooks. Response plans therefore help turn incident-response procedures into repeatable operational workflows rather than relying entirely on individual analyst memory.<\/span><\/p>\n<p><b>Question 174. Which tabs appear on the investigation workbench?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> License, Index, Search<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Users, Roles, Apps<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Alerts, Inputs, Outputs<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Context, Endpoint Data, Network Data<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Context, Endpoint Data, Network Data<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The investigation workbench provides several views that help analysts examine artifacts associated with a case. Splunk documentation identifies Context, Endpoint Data, and Network Data as default tabs. Context panels provide information about assets and identities, endpoint panels can expose file-system or host-related activity, and network panels show network traffic information. Having several views in one workbench reduces the need to switch repeatedly between unrelated tools while investigating the same user, host, file, or URL.<\/span><\/p>\n<p><b>Question 175. What can be added as an investigation artifact?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only dashboards<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Assets, identities, files, or URLs<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only indexes<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only user roles<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Assets, identities, files, or URLs<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Artifacts are investigation objects that analysts add to the scope of a case so they can determine whether those objects are affected by or involved in the incident. Splunk documentation lists assets, identities, files, and URLs as examples of artifacts that can be added to the investigation workbench. By collecting relevant artifacts in one investigation, analysts can pivot between related endpoint, network, and contextual evidence more efficiently. This also provides a clearer record of what objects were examined during the investigation.<\/span><\/p>\n<p><b>Question 176. What does Mission Control provide?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Firmware management<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Index replication<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Analyst queue and investigation workflow<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Field extraction only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Analyst queue and investigation workflow<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Mission Control is the central analyst workflow for triaging, investigating, and responding to security findings and investigations in Splunk Enterprise Security. Its analyst queue displays findings and investigations, while associated views provide timelines, filtering, case details, and response options. Analysts can assign work, update status, start investigations, run actions and playbooks, apply response plans, and use threat intelligence. Splunk describes Mission Control as a collaborative workspace for identifying and remediating security incidents.<\/span><\/p>\n<p><b>Question 177. What does disposition record?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Index size<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Investigation outcome<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Lookup ownership<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Search runtime<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Investigation outcome<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Disposition records the analyst&#8217;s conclusion about a finding or investigation. Splunk Mission Control provides values such as true positive, benign positive, false positive, and undetermined. Updating disposition creates useful feedback about detection quality and helps document the final result of the analyst&#8217;s work. For example, repeated false-positive dispositions may indicate that a detection requires tuning. Disposition is different from status: status tracks workflow progress, while disposition describes the analyst&#8217;s conclusion about what the security activity actually represented.<\/span><\/p>\n<p><b>Question 178. What can an investigation note contain?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only passwords<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only SPL commands<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only risk scores<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Analyst evidence and comments<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Analyst evidence and comments<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Notes allow analysts to attach relevant context and documentation to findings or investigations. Splunk documentation describes notes as supporting information that can include text, screenshots, log extracts, email messages, Splunk events, PDFs, and other reference material. Notes improve collaboration because other analysts can understand what has already been discovered and why certain decisions were made. They also create a useful investigation history for review, escalation, or audit purposes.<\/span><\/p>\n<p><b>Question 179. What is a finding group?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Related findings grouped together<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A data model<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A lookup collection<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> An index cluster<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Related findings grouped together<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A finding group combines related findings so analysts can review them as part of a broader security story. This reduces the need to triage every detection result in isolation when several findings represent connected activity. Splunk Enterprise Security allows finding groups to be added to investigations and supports investigations containing several groups. Grouping helps provide more context, reduce repetitive work, and make coordinated attack activity easier to recognize.<\/span><\/p>\n<p><b>Question 180. What does threat enrichment add?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Context about an indicator<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> More raw events<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Index capacity<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Search permissions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Context about an indicator<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Threat enrichment adds external or internal intelligence context to an observable such as an IP address, domain, URL, or file hash. This context can include reputation, classifications, threat associations, or information from external intelligence providers. Enrichment helps analysts decide whether an observable is likely benign, suspicious, or malicious without relying only on the original event. Splunk&#8217;s threat intelligence features can enrich investigation artifacts and observables so analysts can combine intelligence findings with local evidence before reaching a final conclusion.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Splunk SPLK-5001 Exam Dumps and Practice Test Dumps. Question 161. What is an entity in Enterprise Security? A dashboard A lookup file A search command A subject of suspicious activity Correct Answer: 4. A subject of suspicious activity Explanation: An entity represents a user, system, device, or other object associated with suspicious, anomalous, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21517"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=21517"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21517\/revisions"}],"predecessor-version":[{"id":21518,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21517\/revisions\/21518"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=21517"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=21517"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=21517"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}