ElasticCertified SIEM Analyst
Domain 6Objective 4
Analyze Alerts That Are Generated from Detection Rules ELASTIC-CERTIFIED-SIEM-ANALYST Practice Questions (Page 3)
Part of the Security Application domain, which makes up ~53% of our current practice bank.
23questions here
5free pages
7concepts
Questions 11–15
- 11
When an Elastic Security detection rule generates an alert, which field in the alert document typically contains the rule's unique identifier?
Select an answer first - 12
A SOC analyst is triaging an alert for a potential data exfiltration. The alert shows a large outbound transfer from a server to an external IP. The analyst enriches the alert with threat intelligence and finds that the external IP is a known cloud storage service. What should the analyst do next?
Select an answer first - 13
What is the goal of the eradication phase in incident response?
Select an answer first - 14
A SOC has a limited team and receives a high volume of alerts. The team needs to prioritize alerts effectively. Which approach best balances thoroughness and efficiency?
Select an answer first - 15
A SOC analyst is triaging multiple alerts. Alert A is a medium-severity alert for a single failed login from an internal IP. Alert B is a high-severity alert for multiple failed logins from an external IP targeting a domain admin account. Alert C is a low-severity alert for a successful login from a known employee's account during off-hours. Given limited time, which alert should the analyst prioritize first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Elastic. “ELASTIC-CERTIFIED-SIEM-ANALYST” is a trademark of its owner, used for identification only.