Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Elastic logo

ElasticCertified SIEM Analyst

Domain 1Objective 2

Demonstrate Use of Fleet and Elastic Agents ELASTIC-CERTIFIED-SIEM-ANALYST Practice Questions (Page 5)

Part of the Stack Architecture domain, which makes up ~12% of our current practice bank.

27questions here
6free pages
7concepts

Questions 21–25

  1. 21application · medium

    A security analyst wants to collect Windows Defender logs from a group of Windows endpoints. They have already created an agent policy and enrolled the endpoints. What is the next step to start collecting these logs?

    Select an answer first
  2. 22application · medium

    A Linux admin needs to install Elastic Agent on a new Ubuntu server. The Fleet Server is already running and the admin has a valid enrollment token. Which command should they run on the Ubuntu server?

    Select an answer first
  3. 23foundation · easy

    Where can an administrator verify that an Elastic Agent has successfully enrolled and is active?

    Select an answer first
  4. 24foundation · easy

    Which of the following is a valid method to install an Elastic Agent on a host?

    Select an answer first
  5. 25application · medium

    A company has two groups of servers: web servers that need to ship Nginx access logs and database servers that need to ship PostgreSQL logs. They want to manage these configurations centrally. What is the recommended approach in Fleet?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Elastic. “ELASTIC-CERTIFIED-SIEM-ANALYST” is a trademark of its owner, used for identification only.