ElasticCertified SIEM Analyst
Domain 6Objective 6
Track Security Issues Using Cases ELASTIC-CERTIFIED-SIEM-ANALYST Practice Questions (Page 4)
Part of the Security Application domain, which makes up ~53% of our current practice bank.
36questions here
8free pages
9concepts
Questions 16–20
- 16
An analyst has a large PCAP file (500 MB) that is critical evidence. The team has a policy to keep case attachments under 100 MB. What should the analyst do?
Select an answer first - 17
Which of the following is an example of a file attachment that could be added to a case?
Select an answer first - 18
A case is open for a malware outbreak. The analyst finds a new alert that is related to the same malware. What should the analyst do?
Select an answer first - 19
In Elastic Security, what can a case be assigned to?
Select an answer first - 20
A SOC manager wants to review all cases that are currently open and have a severity of 'high' to prioritize resources. What should the manager do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Elastic. “ELASTIC-CERTIFIED-SIEM-ANALYST” is a trademark of its owner, used for identification only.