Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Elastic logo

ElasticCertified SIEM Analyst

Domain 6Objective 7

Monitor Security-Related Events with Dashboards in the Security App ELASTIC-CERTIFIED-SIEM-ANALYST Practice Questions (Page 5)

Part of the Security Application domain, which makes up ~53% of our current practice bank.

28questions here
6free pages
6concepts

Questions 21–25

  1. 21foundation · easy

    To inspect the individual security events behind a dashboard metric, what should an analyst do?

    Select an answer first
  2. 22application · medium

    A SOC analyst is monitoring the 'Endpoint Security' dashboard and needs to focus only on events from the 'web-server-01' host that occurred in the last hour. The dashboard currently shows all hosts for the last 24 hours. Which sequence of actions should the analyst perform?

    Select an answer first
  3. 23application · medium

    A security analyst wants to add a new panel to the 'Authentication' dashboard that shows 'Top Source IPs' for failed logins. The analyst has already created the visualization in a saved search. What is the next step to add it to the dashboard?

    Select an answer first
  4. 24application · medium

    An analyst is viewing the 'Network' dashboard and sees a large spike in the 'Top Source IPs' visualization. The analyst needs to determine whether this spike represents a real threat or just normal traffic. Which action is most appropriate to investigate the spike?

    Select an answer first
  5. 25foundation · easy

    Which of the following is a prebuilt security dashboard available in the Elastic Security App?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Elastic. “ELASTIC-CERTIFIED-SIEM-ANALYST” is a trademark of its owner, used for identification only.