ElasticCertified SIEM Analyst
Domain 6Objective 7
Monitor Security-Related Events with Dashboards in the Security App ELASTIC-CERTIFIED-SIEM-ANALYST Practice Questions (Page 2)
Part of the Security Application domain, which makes up ~53% of our current practice bank.
28questions here
6free pages
6concepts
Questions 6–10
- 6
A SOC analyst is investigating a security incident and needs to access the 'Endpoint Security' dashboard. The analyst is currently in the 'Security' space but cannot find the dashboard. The analyst knows the dashboard exists because a colleague used it earlier. What is the most likely cause and the best next step?
Select an answer first - 7
In the Elastic Security App, where would an analyst typically go to open the prebuilt security dashboards?
Select an answer first - 8
After modifying a security dashboard by removing a panel, what must the analyst do to keep the change for future sessions?
Select an answer first - 9
An analyst wants to see only security events from the last 24 hours on a dashboard. Which control should they use?
Select an answer first - 10
An analyst wants to add a new visualization panel to an existing security dashboard. What is the first step?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Elastic. “ELASTIC-CERTIFIED-SIEM-ANALYST” is a trademark of its owner, used for identification only.