ElasticCertified SIEM Analyst
Domain 4Objective 1
Create Aggregation-Based Visualizations for Security Use Cases ELASTIC-CERTIFIED-SIEM-ANALYST Practice Questions (Page 3)
Part of the Visualizations domain, which makes up ~13% of our current practice bank.
34questions here
7free pages
15concepts
Questions 11–15
- 11
A security analyst wants to view only events from the last 15 minutes to investigate an ongoing alert. What should they adjust in the visualization?
Select an answer first - 12
To compare the proportion of security events by category (e.g., authentication, network, malware), which visualization type is most appropriate?
Select an answer first - 13
What is the term for combining multiple aggregations, such as a terms aggregation inside a date_histogram, to create multi-level breakdowns?
Select an answer first - 14
Which metric aggregation would you use to compute the average duration of a security process?
Select an answer first - 15
An analyst needs to build a report that lists every combination of user and action (e.g., login, delete, download) with the count of events for each combination. The data contains millions of events and thousands of users. The analyst must ensure the report can be generated without overwhelming the cluster. Which approach should the analyst use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Elastic. “ELASTIC-CERTIFIED-SIEM-ANALYST” is a trademark of its owner, used for identification only.