ElasticCertified SIEM Analyst
Domain 5Objective 2
Demonstrate the Use of Dashboards ELASTIC-CERTIFIED-SIEM-ANALYST Practice Questions (Page 5)
Part of the Dashboards domain, which makes up ~11% of our current practice bank.
26questions here
6free pages
8concepts
Questions 21–25
- 21
A SOC analyst is investigating a suspected brute-force attack and has opened a dashboard showing authentication events. The analyst wants to temporarily narrow the view to only show events from a specific source IP address, without permanently altering the saved dashboard for other team members. What is the most appropriate action?
Select an answer first - 22
Which of the following is a valid way to create a new dashboard in Elastic?
Select an answer first - 23
A security team has been using a dashboard for several months. They have decided to retire it and replace it with a new one. The team wants to remove the old dashboard from Kibana to avoid confusion. What is the most appropriate action?
Select an answer first - 24
A security analyst has a dashboard with a large bar chart showing alerts by user. The analyst wants to make the chart smaller and place it in the top-right corner of the dashboard, next to a line chart. What is the correct way to reposition and resize the panel?
Select an answer first - 25
An analyst is investigating a security incident and has a dashboard with multiple panels. The analyst wants to see only events from the last 24 hours, but the dashboard is currently showing data from the last 7 days. What is the most efficient way to change the time range for the entire dashboard?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Elastic. “ELASTIC-CERTIFIED-SIEM-ANALYST” is a trademark of its owner, used for identification only.