Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Elastic logo

ElasticCertified SIEM Analyst

Domain 4Objective 1

Create Aggregation-Based Visualizations for Security Use Cases ELASTIC-CERTIFIED-SIEM-ANALYST Practice Questions (Page 5)

Part of the Visualizations domain, which makes up ~13% of our current practice bank.

34questions here
7free pages
15concepts

Questions 21–25

  1. 21application · medium

    An analyst wants to compare the number of events from internal IPs versus external IPs over the last 24 hours. The analyst has a field called source.ip and a list of internal IP ranges. Which configuration should be used?

    Select an answer first
  2. 22foundation · easy

    What is the purpose of applying a time range filter to a visualization in Kibana?

    Select an answer first
  3. 23foundation · easy

    Which Elasticsearch aggregation type would you use to count the number of distinct source IP addresses in a security event index?

    Select an answer first
  4. 24foundation · easy

    Which visualization type is best suited for showing the trend of security events over time?

    Select an answer first
  5. 25application · medium

    An analyst needs a dashboard panel that shows the number of distinct users who have failed to authenticate in the last hour. The analyst wants a single number displayed prominently. Which configuration should be used?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Elastic. “ELASTIC-CERTIFIED-SIEM-ANALYST” is a trademark of its owner, used for identification only.