ElasticCertified SIEM Analyst
Domain 6Objective 4
Analyze Alerts That Are Generated from Detection Rules ELASTIC-CERTIFIED-SIEM-ANALYST Practice Questions (Page 4)
Part of the Security Application domain, which makes up ~53% of our current practice bank.
23questions here
5free pages
7concepts
Questions 16–20
- 16
A security analyst receives an alert from a detection rule that flags a single failed login followed by a successful login from the same user within 5 minutes. The alert's `event.action` field shows `authentication_failure` and `authentication_success`, and the `source.ip` is the same. The analyst needs to determine if this alert is a true positive. Which action best validates the alert?
Select an answer first - 17
Which of the following is an example of contextual data that can enrich an alert?
Select an answer first - 18
After investigating a false positive alert, an analyst needs to document the findings. What is the most important information to include in the documentation?
Select an answer first - 19
After determining an alert is a false positive, what is an appropriate follow-up action?
Select an answer first - 20
Which field in an Elastic Security alert document indicates the severity level assigned by the detection rule?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Elastic. “ELASTIC-CERTIFIED-SIEM-ANALYST” is a trademark of its owner, used for identification only.