ElasticCertified SIEM Analyst
Domain 6Objective 7
Monitor Security-Related Events with Dashboards in the Security App ELASTIC-CERTIFIED-SIEM-ANALYST Practice Questions (Page 5)
Part of the Security Application domain, which makes up ~53% of our current practice bank.
28questions here
6free pages
6concepts
Questions 21–25
- 21
To inspect the individual security events behind a dashboard metric, what should an analyst do?
Select an answer first - 22
A SOC analyst is monitoring the 'Endpoint Security' dashboard and needs to focus only on events from the 'web-server-01' host that occurred in the last hour. The dashboard currently shows all hosts for the last 24 hours. Which sequence of actions should the analyst perform?
Select an answer first - 23
A security analyst wants to add a new panel to the 'Authentication' dashboard that shows 'Top Source IPs' for failed logins. The analyst has already created the visualization in a saved search. What is the next step to add it to the dashboard?
Select an answer first - 24
An analyst is viewing the 'Network' dashboard and sees a large spike in the 'Top Source IPs' visualization. The analyst needs to determine whether this spike represents a real threat or just normal traffic. Which action is most appropriate to investigate the spike?
Select an answer first - 25
Which of the following is a prebuilt security dashboard available in the Elastic Security App?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Elastic. “ELASTIC-CERTIFIED-SIEM-ANALYST” is a trademark of its owner, used for identification only.