ElasticCertified SIEM Analyst
Domain 4Objective 1
Create Aggregation-Based Visualizations for Security Use Cases ELASTIC-CERTIFIED-SIEM-ANALYST Practice Questions (Page 4)
Part of the Visualizations domain, which makes up ~13% of our current practice bank.
34questions here
7free pages
15concepts
Questions 16–20
- 16
When building a terms aggregation in Kibana to display the top security threats, which parameter directly controls the order in which the buckets are returned?
Select an answer first - 17
Which aggregation type allows you to create buckets that contain only documents matching a specific query condition, such as all events with `event.category: authentication`?
Select an answer first - 18
Where can a saved visualization be added so that multiple visualizations can be viewed together?
Select an answer first - 19
Which aggregation is designed to paginate through many buckets when grouping by multiple fields, such as `source.ip` and `destination.port`?
Select an answer first - 20
A security analyst needs a dashboard panel showing the top 10 destination ports targeted by inbound traffic over the last 24 hours, ranked by event count. The analyst opens Kibana Lens and selects the appropriate visualization. Which configuration should the analyst use?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Elastic. “ELASTIC-CERTIFIED-SIEM-ANALYST” is a trademark of its owner, used for identification only.