ElasticCertified SIEM Analyst
Domain 5Objective 1
Construct Dashboards for Security Use Cases ELASTIC-CERTIFIED-SIEM-ANALYST Practice Questions (Page 5)
Part of the Dashboards domain, which makes up ~11% of our current practice bank.
22questions here
5free pages
8concepts
Questions 21–22
- 21
A SOC team wants to visualize the number of failed login attempts per user over the last 24 hours to identify potential brute-force attacks. They have authentication logs in the 'auth-*' index. Which visualization configuration is most appropriate?
Select an answer first - 22
A SOC analyst is using a dashboard to investigate a phishing campaign. They want to click on a specific sender in a visualization and see all emails from that sender in a detailed table below. Which interactive feature should they configure?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to ELASTIC-CERTIFIED-SIEM-ANALYST
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Elastic. “ELASTIC-CERTIFIED-SIEM-ANALYST” is a trademark of its owner, used for identification only.