{"id":21519,"date":"2026-09-25T05:53:52","date_gmt":"2026-09-25T05:53:52","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=21519"},"modified":"2026-09-25T05:53:52","modified_gmt":"2026-09-25T05:53:52","slug":"splunk-splk-5001-practice-test-questions-and-exam-dumps-part10-q181-200","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/splunk-splk-5001-practice-test-questions-and-exam-dumps-part10-q181-200\/","title":{"rendered":"Splunk SPLK-5001 Practice Test Questions and Exam Dumps Part10 Q181-200"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/splk-5001-exam-dumps\"><b>Splunk SPLK-5001 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Question 181. What is a vulnerability?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A confirmed attack<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A threat actor<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A weakness that can be exploited<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A risk score<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. A weakness that can be exploited<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A vulnerability is a weakness in software, hardware, configuration, or a security process that an attacker may be able to exploit. Examples include unpatched software, weak permissions, exposed services, or insecure configurations. A vulnerability does not automatically mean a system has been compromised. Analysts combine vulnerability information with asset importance, threat intelligence, and observed activity to determine actual risk. The SPLK-5001 blueprint includes risk management and cyber defense concepts that require analysts to understand weaknesses, threats, and their potential impact.<\/span><\/p>\n<p><b>Question 182. What does CVE provide?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A standard vulnerability identifier<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> An asset risk score<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A Splunk field name<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A threat-hunting method<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. A standard vulnerability identifier<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A CVE identifier provides a standardized name for a publicly disclosed cybersecurity vulnerability. This allows vendors, scanners, analysts, and security tools to refer to the same weakness consistently. CVE information is often combined with severity information, affected-product details, exploit intelligence, and local asset context. For a SOC analyst, a CVE alone does not determine urgency. A critical vulnerability on an isolated test system may represent less immediate risk than a moderately rated vulnerability on an internet-facing production system under active attack.<\/span><\/p>\n<p><b>Question 183. What does CVSS estimate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> User identity<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Detection frequency<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Asset ownership<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Vulnerability severity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Vulnerability severity<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Common Vulnerability Scoring System provides a standardized method for expressing the severity of a vulnerability. Scores consider technical characteristics such as attack complexity, privileges required, user interaction, scope, and potential confidentiality, integrity, and availability impact. CVSS is useful for prioritization, but analysts should not rely on it alone. Local asset criticality, exposure, active exploitation, threat intelligence, and compensating controls can significantly change how urgently an organization should respond to a vulnerability.<\/span><\/p>\n<p><b>Question 184. What is a false positive?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Missed malicious activity<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Benign activity flagged as malicious<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Confirmed compromise<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Deleted evidence<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Benign activity flagged as malicious<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A false positive occurs when a detection identifies legitimate behavior as suspicious or malicious. Too many false positives can overwhelm analysts and reduce confidence in detections. Detection tuning aims to lower unnecessary alert volume while preserving coverage for real threats. Splunk recommends reviewing common field values, recurring patterns, and sample events to identify root causes of detection noise and exclude only clearly benign activity. Proper tuning should reduce noise without hiding genuine malicious behavior.<\/span><\/p>\n<p><b>Question 185. What is a false negative?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Benign activity flagged<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Duplicate finding<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Suppressed alert<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Malicious activity not detected<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Malicious activity not detected<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A false negative occurs when malicious activity happens but the detection logic fails to identify it. False negatives are dangerous because they create a misleading impression that the environment is safe. They can result from missing data, weak detection logic, overly aggressive exclusions, incorrect thresholds, or attacker behavior outside known patterns. Security teams should balance noise reduction against coverage so tuning does not remove important evidence. Threat hunting can also help uncover activity that existing detections missed.<\/span><\/p>\n<p><b>Question 186. What is detection tuning?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Adjusting logic to improve accuracy<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Deleting all alerts<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disabling data sources<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Changing usernames<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Adjusting logic to improve accuracy<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Detection tuning improves detection quality by adjusting search logic, thresholds, exclusions, or other conditions based on observed results. Splunk describes tuning as analyzing detection output to identify patterns that create unnecessary alert noise and modifying the detection so benign behavior is excluded while meaningful threat coverage remains. Tuning is part of the detection lifecycle and should be repeated as user behavior, applications, infrastructure, and attacker techniques change over time.<\/span><\/p>\n<p><b>Question 187. Why use an allowlist?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Increase every risk score<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Exclude known benign activity<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Delete raw data<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Create new indexes<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Exclude known benign activity<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An allowlist identifies known legitimate values or behaviors that should not generate certain security findings. Examples might include approved vulnerability scanners, trusted administrative scripts, or sanctioned external services. Allowlisting can reduce false positives, but it should be narrowly scoped. A broad exclusion can create blind spots that attackers may exploit. Analysts should document why a value is allowlisted and review the exception periodically to confirm that the underlying business justification is still valid.<\/span><\/p>\n<p><b>Question 188. What is a detection threshold?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> An index limit<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A retention period<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A condition that must be exceeded<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A dashboard filter<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. A condition that must be exceeded<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A detection threshold defines the level of activity required before a detection generates a finding or another response. For example, five failed logins in one hour may be normal, while fifty failures in five minutes may justify investigation. Thresholds should reflect the environment&#8217;s normal behavior and risk tolerance. Values set too low can create large amounts of noise, while values set too high can miss attacks. Splunk recommends tuning thresholds and risk levels as operational conditions change.<\/span><\/p>\n<p><b>Question 189. What does attack surface mean?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Exposed opportunities for attack<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> One malware sample<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> One Splunk index<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A SOC dashboard<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Exposed opportunities for attack<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The attack surface includes the systems, services, identities, applications, interfaces, and configurations an attacker could potentially target. Internet-facing servers, cloud permissions, remote-access services, user accounts, APIs, and endpoints can all contribute to the attack surface. Reducing unnecessary services, enforcing least privilege, patching vulnerabilities, and limiting exposure can shrink it. Analysts use asset, vulnerability, and threat information to understand where the environment is most exposed and where monitoring should be strongest.<\/span><\/p>\n<p><b>Question 190. What is defense in depth?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> One strong firewall only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> One detection rule<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> One antivirus product<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Multiple layers of security controls<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Multiple layers of security controls<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Defense in depth uses several complementary controls so failure of one layer does not automatically lead to complete compromise. Layers may include identity controls, endpoint protection, firewalls, network segmentation, vulnerability management, monitoring, backups, and incident response. A phishing message might bypass an email filter but still be stopped by endpoint controls or detected through authentication and network telemetry. This layered approach is consistent with the broader cyber defense and control concepts included in the SPLK-5001 blueprint.<\/span><\/p>\n<p><b>Question 191. What is least privilege?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Maximum access for admins<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Minimum access needed<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> No authentication<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Shared accounts<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Minimum access needed<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Least privilege means giving users, applications, and systems only the permissions required to perform their legitimate functions. Restricting privilege reduces the impact of compromised accounts and limits opportunities for lateral movement or unauthorized actions. Analysts often investigate unexpected privilege changes, use of administrator accounts, or access outside normal job requirements. Least privilege works together with role-based access, identity monitoring, and zero-trust principles to reduce unnecessary exposure.<\/span><\/p>\n<p><b>Question 192. What is a compensating control?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A deleted control<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A failed detection<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> An alternative control reducing risk<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A password reset<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. An alternative control reducing risk<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A compensating control is an alternative safeguard used when the preferred security control cannot be implemented immediately or completely. For example, if an old application cannot be patched, network isolation, stronger monitoring, restricted access, and application allowlisting may reduce the associated risk. A compensating control does not necessarily eliminate the original vulnerability. Analysts should understand these controls when evaluating alerts because the same technical weakness can represent different levels of practical risk depending on surrounding defenses.<\/span><\/p>\n<p><b>Question 193. What does NIST CSF Detect cover?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Backups only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Purchasing systems<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> User onboarding only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Identifying cybersecurity events<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Identifying cybersecurity events<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Detect function of the NIST Cybersecurity Framework focuses on discovering cybersecurity events and anomalies. Monitoring, continuous analysis, detection processes, and alerting all support this function. Splunk security monitoring fits naturally into Detect because Splunk collects and analyzes events from identity, endpoint, network, cloud, and other sources. The SPLK-5001 blueprint expects candidates to recognize common security frameworks and understand how Splunk capabilities support those frameworks.<\/span><\/p>\n<p><b>Question 194. What does NIST CSF Respond cover?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Hardware purchasing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Actions after detecting an incident<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Network addressing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Software licensing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Actions after detecting an incident<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Respond function covers activities performed after a cybersecurity incident is detected. Examples include analysis, communication, containment, mitigation, coordination, and improvements to response processes. In Splunk environments, analysts may investigate findings, gather evidence, escalate incidents, and trigger adaptive-response or SOAR workflows. Respond differs from Detect because detection identifies suspicious activity, while response focuses on what the organization does once the threat is recognized.<\/span><\/p>\n<p><b>Question 195. What does NIST CSF Recover focus on?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Restoring capabilities<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Threat hunting only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Alert suppression<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Asset discovery only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Restoring capabilities<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Recover function focuses on restoring services, systems, and business capabilities after a cybersecurity incident. Recovery planning, backups, service restoration, communication, and lessons learned can all support this function. Recovery is especially important after ransomware, destructive attacks, or major service disruption. Analysts may contribute by providing timelines, affected-asset information, and evidence about what must be remediated before systems return to normal operation.<\/span><\/p>\n<p><b>Question 196. What does UEBA compare?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> License counts<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Dashboard colors<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Current behavior with baselines<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Index names<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Current behavior with baselines<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">User and Entity Behavior Analytics identifies unusual activity by comparing current behavior with learned historical baselines. Rather than relying only on fixed thresholds, UEBA models what is normal for a particular user or asset and flags meaningful deviations. Splunk documents UEBA detections as generating intermediate findings when behavior differs significantly from the established baseline. These findings can contribute to the entity risk score and help analysts identify compromised accounts or unusual system behavior.<\/span><\/p>\n<p><b>Question 197. What is entity risk score?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Index storage usage<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Overall risk level of an entity<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Search runtime<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Number of dashboards<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Overall risk level of an entity<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The entity risk score represents the overall risk associated with an entity such as a user or asset based on recent findings. Current Splunk Enterprise Security documentation describes the score as normalized from 0 to 100 and calculated from recent intermediate findings. The scoring model considers how often detections fire for the entity and how noisy those detections are across the environment. Higher scores help analysts identify entities that may require more immediate investigation.<\/span><\/p>\n<p><b>Question 198. What can asset criticality influence?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Browser version<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Field extraction<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Search syntax<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Risk prioritization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Risk prioritization<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Asset criticality provides business context that can influence how security events are prioritized. Suspicious activity involving a critical domain controller or production database may deserve more attention than the same behavior on a temporary test system. Splunk risk factors can use asset and identity metadata such as priority, category, user, or asset type to increase or decrease calculated risk. This lets the scoring process account for the importance of the affected entity.<\/span><\/p>\n<p><b>Question 199. What can excessive alert volume indicate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Perfect tuning<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> No threats exist<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Detection tuning may be needed<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Logs should be deleted<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Detection tuning may be needed<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Very high alert volume can indicate that detection logic is too broad, thresholds are too low, benign behavior is not excluded, or duplicate detections are firing on the same activity. Splunk recommends systematically reviewing detection results, common field values, prevalence, and sample events to identify sources of noise. Tuning can reduce false positives and analyst workload while retaining coverage of real threats. High volume should lead to analysis and refinement, not automatic dismissal of all alerts.<\/span><\/p>\n<p><b>Question 200. What BEST improves detection quality?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Test, tune, and review detections<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Never change detection logic<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Ignore false positives<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Alert on every event<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Test, tune, and review detections<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Effective detections require an ongoing lifecycle rather than one-time creation. Analysts should validate the underlying logic, review results, identify false positives, adjust thresholds and exclusions, monitor changes in behavior, and periodically confirm that the detection still covers the intended threat. Splunk describes detection tuning as a systematic process for reducing noise while amplifying meaningful threats. Continuous review improves both analyst efficiency and the likelihood that important malicious activity receives attention.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Splunk SPLK-5001 Exam Dumps and Practice Test Dumps. Question 181. What is a vulnerability? A confirmed attack A threat actor A weakness that can be exploited A risk score Correct Answer: 3. A weakness that can be exploited Explanation: A vulnerability is a weakness in software, hardware, configuration, or a security process that [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21519"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=21519"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21519\/revisions"}],"predecessor-version":[{"id":21520,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/21519\/revisions\/21520"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=21519"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=21519"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=21519"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}