ElasticCertified SIEM Analyst
Domain 4Objective 1
Create Aggregation-Based Visualizations for Security Use Cases ELASTIC-CERTIFIED-SIEM-ANALYST Practice Questions (Page 5)
Part of the Visualizations domain, which makes up ~13% of our current practice bank.
34questions here
7free pages
15concepts
Questions 21–25
- 21
An analyst wants to compare the number of events from internal IPs versus external IPs over the last 24 hours. The analyst has a field called source.ip and a list of internal IP ranges. Which configuration should be used?
Select an answer first - 22
What is the purpose of applying a time range filter to a visualization in Kibana?
Select an answer first - 23
Which Elasticsearch aggregation type would you use to count the number of distinct source IP addresses in a security event index?
Select an answer first - 24
Which visualization type is best suited for showing the trend of security events over time?
Select an answer first - 25
An analyst needs a dashboard panel that shows the number of distinct users who have failed to authenticate in the last hour. The analyst wants a single number displayed prominently. Which configuration should be used?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Elastic. “ELASTIC-CERTIFIED-SIEM-ANALYST” is a trademark of its owner, used for identification only.