ElasticCertified SIEM Analyst
Domain 6Objective 7
Monitor Security-Related Events with Dashboards in the Security App ELASTIC-CERTIFIED-SIEM-ANALYST Practice Questions (Page 3)
Part of the Security Application domain, which makes up ~53% of our current practice bank.
28questions here
6free pages
6concepts
Questions 11–15
- 11
To view only security events from a specific host on a dashboard, which action should the analyst take?
Select an answer first - 12
An analyst is viewing the 'Security Overview' dashboard and sees a table with 'Top Alerts'. The analyst wants to see the full event details for a specific alert, including the raw JSON. What is the best way to do this?
Select an answer first - 13
A security analyst needs to quickly review the last 30 minutes of failed authentication attempts across all Windows servers. The analyst opens the Security App and wants to land directly on the most relevant prebuilt dashboard. Which action should the analyst take first?
Select an answer first - 14
While viewing a bar chart on a security dashboard, an analyst clicks on a bar representing 'high' severity events. What is the expected outcome?
Select an answer first - 15
An analyst is looking at the 'DNS' dashboard and sees a visualization titled 'Top DNS Queries by Count'. The analyst wants to understand which specific domains are generating the most traffic and then investigate one of them. What should the analyst do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Elastic. “ELASTIC-CERTIFIED-SIEM-ANALYST” is a trademark of its owner, used for identification only.