Try 12 Elastic Certified SIEM Analyst practice-readiness questions on Elastic Security, alerts, timelines, detection rules, endpoint data, case workflow, threat hunting, and investigation decisions.
Elastic Certified SIEM Analyst is a security-operations route for candidates who use Elastic Security to triage alerts, investigate endpoint and network evidence, build timelines, manage cases, and reason through detection and threat-hunting workflows.
Use this page to try original IT Mastery sample questions on SIEM decisions. They are not official Elastic exam questions.
Practice option: Sample questions available
Start with the 12 sample questions on this page. Dedicated practice for Elastic Certified SIEM Analyst is not currently included as a full web-app practice page; enter your email to get updates when full practice becomes available or expands for this exam.
Need live practice now? See currently available IT Mastery exam pages.
Topic: alert triage
An alert shows suspicious PowerShell with encoded command text, outbound network activity, and a rare parent process. What should the analyst do first?
Best answer: A
Explanation: Multiple suspicious indicators justify investigation. The analyst should preserve evidence and correlate host, user, process, and network context.
Topic: timelines
Why add related events to a timeline?
Best answer: C
Explanation: Timelines help analysts connect related events and explain what happened. They support handoff and review.
Topic: detection rules
A rule fires frequently on an approved admin script. What should be considered?
Best answer: B
Explanation: Tuning should reduce expected noise without hiding real misuse. Exceptions should be scoped and reviewed.
Topic: endpoint data
Which endpoint fields are most useful when investigating suspicious process execution?
Best answer: D
Explanation: Process lineage, command line, user, host, hash, and network context help determine whether execution is suspicious.
Topic: cases
When should an analyst create or update a case?
Best answer: A
Explanation: Cases support workflow, ownership, notes, and task tracking. They are useful when investigation needs coordination or follow-up.
Topic: threat hunting
A hunt looks for unusual outbound connections from servers that normally do not access the internet. What data is most relevant?
Best answer: C
Explanation: The hunt needs network, host, destination, process, and timing evidence. Host role context makes “unusual” meaningful.
Topic: user context
Why include user context in endpoint investigations?
Best answer: B
Explanation: User context helps determine impact and likelihood. Privileged users or unusual behavior can raise urgency.
Topic: escalation
Which finding most strongly supports escalation?
Best answer: D
Explanation: Multiple indicators involving credentials, privilege, execution, and network activity raise confidence and impact.
Topic: investigation notes
What should good investigation notes include?
Best answer: A
Explanation: Notes make the investigation inspectable and transferable. They should explain both evidence and reasoning.
Topic: false positives
A detection is accurate but creates too many low-value alerts. What should be reviewed?
Best answer: C
Explanation: Detections should be actionable. Tuning can preserve useful findings while reducing noise.
Topic: entity risk
Why combine host and user risk context?
Best answer: B
Explanation: Entity risk can highlight patterns across alerts. It supports prioritization but does not replace analyst judgment.
Topic: response coordination
Before isolating a critical server, what should be considered?
Best answer: D
Explanation: Containment actions can affect business services. Analysts should balance urgency, evidence, authorization, and communication.
| If you miss… | Drill this next |
|---|---|
| triage questions | process, network, host, user, and timeline evidence |
| detection questions | rule scope, exceptions, severity, and false-positive tuning |
| workflow questions | timelines, cases, notes, ownership, and escalation |
| response questions | containment, business impact, evidence, and communication |