Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Elastic logo

ElasticCertified SIEM Analyst

Domain 4Objective 1

Create Aggregation-Based Visualizations for Security Use Cases ELASTIC-CERTIFIED-SIEM-ANALYST Practice Questions (Page 1)

Part of the Visualizations domain, which makes up ~13% of our current practice bank.

34questions here
7free pages
15concepts

Questions 1–5

  1. 1foundation · easy

    Which Kibana feature allows users to create visualizations interactively by dragging and dropping fields, without writing Elasticsearch queries?

    Select an answer first
  2. 2foundation · easy

    To create a visualization showing the number of security events per day for the last week, which aggregation should be used as the primary bucket?

    Select an answer first
  3. 3foundation · easy

    Which Elasticsearch aggregation would you use to group security events by the `destination.port` field to see which ports are most frequently targeted?

    Select an answer first
  4. 4expert · hard

    An analyst needs to build a table in Kibana showing all combinations of source IP and destination port, with a count of events for each combination. The data set contains over 100,000 unique source IPs and the table must be fully paginated so the analyst can scroll through every combination. The analyst is using the Elasticsearch aggregations API directly. Which aggregation should the analyst use?

    Select an answer first
  5. 5foundation · easy

    What is the purpose of saving a visualization in Kibana?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Elastic. “ELASTIC-CERTIFIED-SIEM-ANALYST” is a trademark of its owner, used for identification only.