ElasticCertified SIEM Analyst
Domain 6Objective 1
Recognize the Capabilities of the Security App ELASTIC-CERTIFIED-SIEM-ANALYST Practice Questions (Page 2)
Part of the Security Application domain, which makes up ~53% of our current practice bank.
35questions here
7free pages
10concepts
Questions 6–10
- 6
Which action can an analyst perform directly on an alert from the Alerts page?
Select an answer first - 7
During an incident investigation, an analyst discovers a series of related alerts across multiple hosts. The analyst needs to document the findings, attach evidence from a Timeline, and assign tasks to other team members. What feature should the analyst use?
Select an answer first - 8
What is the primary purpose of the Security App in Elastic SIEM?
Select an answer first - 9
Which UI element in the Security App provides a quick overview of the current security posture, including counts of alerts and cases?
Select an answer first - 10
A security analyst is reviewing the risk scores of hosts and users in the Security App. The analyst notices that a host has a high risk score but no associated alerts. The analyst wants to understand why the risk score is high and determine if there is any underlying suspicious activity. What should the analyst do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Elastic. “ELASTIC-CERTIFIED-SIEM-ANALYST” is a trademark of its owner, used for identification only.