Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Elastic logo

ElasticCertified SIEM Analyst

Domain 3Objective 1

Customize the Discover Interface to Search for Data ELASTIC-CERTIFIED-SIEM-ANALYST Practice Questions (Page 3)

Part of the Discover domain, which makes up ~5% of our current practice bank.

23questions here
5free pages
6concepts

Questions 11–15

  1. 11application · medium

    During an investigation, an analyst wants to quickly understand the distribution of event types in the current result set. The analyst has already run a search that returns thousands of events. Which action would give the analyst a quick visual summary of the event.category field values?

    Select an answer first
  2. 12application · medium

    An analyst has configured a Discover view with a specific query, filters, and a custom set of columns. The analyst wants to return to this exact view later without recreating it. What should the analyst do?

    Select an answer first
  3. 13foundation · easy

    A colleague has saved a search named `Failed Logins - Last 24h` in the shared Kibana space. How can an analyst open this saved search in Discover?

    Select an answer first
  4. 14foundation · easy

    An analyst wants to view the most recent events first in Discover. What is the correct way to sort results by the `@timestamp` field in descending order?

    Select an answer first
  5. 15application · medium

    An analyst has a saved search that returns events for a specific user. The analyst now wants to modify the search to also include events from a second user. What is the correct way to update the saved search?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Elastic. “ELASTIC-CERTIFIED-SIEM-ANALYST” is a trademark of its owner, used for identification only.