Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Elastic logo

ElasticCertified SIEM Analyst

Domain 2Objective 1

Examine the Application and Guidelines of ECS ELASTIC-CERTIFIED-SIEM-ANALYST Practice Questions (Page 2)

Part of the Elastic Common Schema (ECS) domain, which makes up ~5% of our current practice bank.

23questions here
5free pages
6concepts

Questions 6–10

  1. 6application · medium

    A security analyst is looking at an event and sees the field 'process.executable'. What does this field represent?

    Select an answer first
  2. 7expert · hard

    An analyst is investigating a security incident and needs to correlate events based on the time they occurred. The logs come from different time zones and some lack timezone information. What is the best practice for handling timestamps in ECS?

    Select an answer first
  3. 8foundation · easy

    Which ECS data type should be used for a field that stores an IPv6 address?

    Select an answer first
  4. 9application · medium

    An analyst is documenting a security event that occurred on January 15, 2023, at 10:30:45 UTC. Which ECS field and format should they use?

    Select an answer first
  5. 10application · medium

    A security team is using Elastic Agent to collect logs. They want to ensure that the data is ECS-compliant before it reaches Elasticsearch. What is the recommended approach?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Elastic. “ELASTIC-CERTIFIED-SIEM-ANALYST” is a trademark of its owner, used for identification only.