ElasticCertified SIEM Analyst
Domain 6Objective 7
Monitor Security-Related Events with Dashboards in the Security App ELASTIC-CERTIFIED-SIEM-ANALYST Practice Questions (Page 6)
Part of the Security Application domain, which makes up ~53% of our current practice bank.
28questions here
6free pages
6concepts
Questions 26–28
- 26
While reviewing the 'Security Overview' dashboard, an analyst notices a high number of 'Failed Logins' in a table visualization. The analyst needs to see the specific usernames and source IPs for these failed attempts. What is the most efficient way to do this?
Select an answer first - 27
A new analyst is joining the SOC team and needs to access the prebuilt 'Endpoint Security' dashboard. The analyst is logged into Kibana but does not see the dashboard in the list. What is the most likely reason and solution?
Select an answer first - 28
An analyst is monitoring the 'Network' dashboard and sees a steady increase in the 'Bytes Sent' metric over the last hour. The analyst wants to determine if this is a gradual trend or a sudden spike. What should the analyst do?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to ELASTIC-CERTIFIED-SIEM-ANALYST
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Elastic. “ELASTIC-CERTIFIED-SIEM-ANALYST” is a trademark of its owner, used for identification only.