ElasticCertified SIEM Analyst
Domain 6Objective 5
Correlate Relevant Data Using Timeline ELASTIC-CERTIFIED-SIEM-ANALYST Practice Questions (Page 4)
Part of the Security Application domain, which makes up ~53% of our current practice bank.
20questions here
4free pages
5concepts
Questions 16–20
- 16
Which of the following can be added to a Timeline?
Select an answer first - 17
An analyst is investigating a series of alerts that suggest a user account is being used from two different geographic locations within a short time frame. The analyst suspects a compromised account. They have a Timeline with the authentication events. What is the most effective way to use the Timeline to confirm this suspicion?
Select an answer first - 18
A SOC team is establishing a standard procedure for investigating alerts. They want to ensure that all analysts follow a consistent workflow when using Timelines. What is a key component of a systematic Timeline investigation workflow?
Select an answer first - 19
A SOC team is investigating a multi-stage phishing campaign. They have created a Timeline with a series of events from the initial email, the user clicking the link, and the subsequent beaconing traffic. The team wants to ensure this Timeline is available to other analysts in the SOC and can be referenced in their final incident report. What is the most appropriate way to manage this Timeline?
Select an answer first - 20
An analyst is investigating a potential data exfiltration incident. They have a Timeline with several authentication events from a compromised user account. They now want to add the corresponding network traffic events from the firewall logs to the same Timeline to see if data was transferred. How can the analyst add these firewall events to the existing Timeline?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to ELASTIC-CERTIFIED-SIEM-ANALYST
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Elastic. “ELASTIC-CERTIFIED-SIEM-ANALYST” is a trademark of its owner, used for identification only.