ElasticCertified SIEM Analyst
Domain 3Objective 1
Customize the Discover Interface to Search for Data ELASTIC-CERTIFIED-SIEM-ANALYST Practice Questions (Page 3)
Part of the Discover domain, which makes up ~5% of our current practice bank.
23questions here
5free pages
6concepts
Questions 11–15
- 11
During an investigation, an analyst wants to quickly understand the distribution of event types in the current result set. The analyst has already run a search that returns thousands of events. Which action would give the analyst a quick visual summary of the event.category field values?
Select an answer first - 12
An analyst has configured a Discover view with a specific query, filters, and a custom set of columns. The analyst wants to return to this exact view later without recreating it. What should the analyst do?
Select an answer first - 13
A colleague has saved a search named `Failed Logins - Last 24h` in the shared Kibana space. How can an analyst open this saved search in Discover?
Select an answer first - 14
An analyst wants to view the most recent events first in Discover. What is the correct way to sort results by the `@timestamp` field in descending order?
Select an answer first - 15
An analyst has a saved search that returns events for a specific user. The analyst now wants to modify the search to also include events from a second user. What is the correct way to update the saved search?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Elastic. “ELASTIC-CERTIFIED-SIEM-ANALYST” is a trademark of its owner, used for identification only.