Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Elastic logo

ElasticCertified SIEM Analyst

Domain 6Objective 4

Analyze Alerts That Are Generated from Detection Rules ELASTIC-CERTIFIED-SIEM-ANALYST Practice Questions (Page 2)

Part of the Security Application domain, which makes up ~53% of our current practice bank.

23questions here
5free pages
7concepts

Questions 6–10

  1. 6foundation · easy

    Which response action is most appropriate when an alert confirms an active malware infection on a critical server?

    Select an answer first
  2. 7foundation · easy

    To validate an alert generated by a detection rule, an analyst should examine which of the following?

    Select an answer first
  3. 8application · medium

    An analyst is reviewing an alert from a detection rule. The alert's `event.category` is `network`, `event.action` is `connection`, and `destination.ip` is a known malicious IP. The analyst wants to verify if the connection was successful. Which field should the analyst examine?

    Select an answer first
  4. 9application · medium

    An alert from a detection rule indicates that a user downloaded a suspicious file from an external URL. The analyst wants to confirm the alert by correlating it with the underlying events. Which data source should the analyst examine first?

    Select an answer first
  5. 10expert · hard

    A detection rule generates an alert with `event.category: file` and `event.action: modification`. The alert includes `file.path`, `file.hash`, and `process.name`. The analyst needs to determine if the file modification is malicious. Which combination of fields provides the most critical evidence?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Elastic. “ELASTIC-CERTIFIED-SIEM-ANALYST” is a trademark of its owner, used for identification only.