ElasticCertified SIEM Analyst
Domain 6Objective 7
Monitor Security-Related Events with Dashboards in the Security App ELASTIC-CERTIFIED-SIEM-ANALYST Practice Questions (Page 4)
Part of the Security Application domain, which makes up ~53% of our current practice bank.
28questions here
6free pages
6concepts
Questions 16–20
- 16
An analyst is monitoring the 'Security Overview' dashboard and sees a visualization showing 'Top Attack Signatures'. The analyst notices a sudden increase in a specific signature and wants to determine if this is a false positive or a real attack. The analyst needs to see the source IPs and timestamps of the events. What is the most effective approach?
Select an answer first - 17
On a security dashboard, a bar chart shows the count of security events by severity. What does the height of each bar represent?
Select an answer first - 18
To have a security dashboard automatically update every 30 seconds, which control should the analyst configure?
Select an answer first - 19
A SOC manager wants the 'Network' dashboard to show a specific set of panels that are most relevant to their team's daily monitoring. They want to create a personalized version without affecting the default dashboard. What should the manager do?
Select an answer first - 20
A security analyst is investigating a phishing campaign and wants to see all events related to a specific user 'jdoe' on the 'Security Overview' dashboard. The analyst also wants to see the details of each event. What is the most efficient approach?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Elastic. “ELASTIC-CERTIFIED-SIEM-ANALYST” is a trademark of its owner, used for identification only.