Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Elastic logo

ElasticCertified SIEM Analyst

Domain 2Objective 1

Examine the Application and Guidelines of ECS ELASTIC-CERTIFIED-SIEM-ANALYST Practice Questions (Page 1)

Part of the Elastic Common Schema (ECS) domain, which makes up ~5% of our current practice bank.

23questions here
5free pages
6concepts

Questions 1–5

  1. 1application · medium

    An organization is ingesting logs from a custom application. They want to include the application's version. Which ECS field should they use?

    Select an answer first
  2. 2foundation · easy

    Which tool or feature in the Elastic Stack can be used to validate that data is ECS-compliant?

    Select an answer first
  3. 3application · medium

    A security team is ingesting firewall logs into Elasticsearch. They want to represent the source IP address of each connection. According to ECS, which field should they use?

    Select an answer first
  4. 4foundation · easy

    Which ECS field category would contain the field for the source IP address of a network connection?

    Select an answer first
  5. 5expert · hard

    An organization is ingesting logs from a custom application that uses a field 'user_id' to identify users. They want to map this to ECS. Which field should they use?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Elastic. “ELASTIC-CERTIFIED-SIEM-ANALYST” is a trademark of its owner, used for identification only.