ElasticCertified SIEM Analyst
Domain 4Objective 1
Create Aggregation-Based Visualizations for Security Use Cases ELASTIC-CERTIFIED-SIEM-ANALYST Practice Questions (Page 2)
Part of the Visualizations domain, which makes up ~13% of our current practice bank.
34questions here
7free pages
15concepts
Questions 6–10
- 6
An analyst is building a dashboard that includes a terms aggregation on source.ip with a size of 10,000 to show all source IPs. The dashboard becomes very slow and times out. The analyst needs to maintain the ability to see all source IPs but must improve performance. Which approach should the analyst take?
Select an answer first - 7
A SOC manager wants a single dashboard panel that shows, side by side, the count of malware detection events and the count of phishing detection events over the last 7 days. The analyst decides to use Kibana Lens. Which approach should the analyst take?
Select an answer first - 8
A security engineer wants to understand the distribution of DNS response times to determine a baseline for anomaly detection. The engineer needs to know the 50th, 95th, and 99th percentile response times for all DNS queries in the last 24 hours. Which visualization configuration should be used?
Select an answer first - 9
Which aggregation type is used to analyze the distribution of a metric, such as finding the 95th percentile of response times?
Select an answer first - 10
An analyst has created a useful bar chart in Kibana Lens showing failed logins by user. The analyst wants to add this chart to a security dashboard so other team members can view it. What is the correct sequence of actions?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Elastic. “ELASTIC-CERTIFIED-SIEM-ANALYST” is a trademark of its owner, used for identification only.