Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Elastic logo

ElasticCertified SIEM Analyst

Domain 6Objective 3

Describe How the Detection Engine Searches Activity and Generates Alerts ELASTIC-CERTIFIED-SIEM-ANALYST Practice Questions (Page 2)

Part of the Security Application domain, which makes up ~53% of our current practice bank.

27questions here
6free pages
5concepts

Questions 6–10

  1. 6application · medium

    A security analyst notices that a specific detection rule has not generated any alerts in the past week, despite a known increase in suspicious activity. The rule is a query rule that searches the logs-* index pattern. The analyst checks the rule's configuration and sees that the rule is enabled and the schedule is set to run every 5 minutes. What is the most likely reason the rule is not generating alerts?

    Select an answer first
  2. 7application · medium

    A security team wants to ensure that detection rules are executed continuously and promptly to minimize the time between an event occurring and an alert being generated. They have a mix of query, threshold, and correlation rules. What is the primary mechanism the Detection Engine uses to achieve this?

    Select an answer first
  3. 8foundation · easy

    What happens when a detection rule's search criteria are met?

    Select an answer first
  4. 9foundation · easy

    Which rule type is designed to generate an alert when the number of matching events reaches a specified threshold?

    Select an answer first
  5. 10expert · hard

    A detection engineer is tuning a threshold rule that detects multiple failed login attempts from the same source IP. The rule currently groups by source IP and triggers when the count exceeds 10 within 5 minutes. The team is seeing too many alerts from a few legitimate users who frequently mistype passwords. They want to reduce false positives while still detecting brute-force attacks. What should the engineer do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Elastic. “ELASTIC-CERTIFIED-SIEM-ANALYST” is a trademark of its owner, used for identification only.