ElasticCertified SIEM Analyst
Domain 6Objective 1
Recognize the Capabilities of the Security App ELASTIC-CERTIFIED-SIEM-ANALYST Practice Questions (Page 6)
Part of the Security Application domain, which makes up ~53% of our current practice bank.
35questions here
7free pages
10concepts
Questions 26–30
- 26
An organization uses Elastic Agent to collect endpoint data, and also ingests network flow logs from a third-party firewall. The security team wants to ensure that alerts generated from both data sources appear in the Security App's Alerts page. What is required for this to happen?
Select an answer first - 27
What does a user's risk score on the User page represent?
Select an answer first - 28
What is the purpose of the 'External alerts' section in the Security App?
Select an answer first - 29
An analyst is investigating a potential lateral movement attack. The analyst has identified a compromised host and wants to see all network connections and processes on that host around the time of the compromise, and also wants to correlate this with any alerts triggered. What should the analyst do?
Select an answer first - 30
In the Security App, where would an analyst go to see a list of all detection alerts?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Elastic. “ELASTIC-CERTIFIED-SIEM-ANALYST” is a trademark of its owner, used for identification only.