1.1 Elastic Certified SIEM Analyst Exam Facts, Objectives & Study Plan
Key Takeaways
The Elastic Certified SIEM Analyst exam is a timed cognitive exam (multiple choice, select all that apply, fill in the blanks, true/false) based on Elastic Stack 8.15.
Elastic lists the exam at $400 USD per attempt with a 2-hour duration, and each purchased attempt must be used within one year.
Elastic does not publish the number of questions, the passing score or the domain weights for the SIEM Analyst exam.
After a failed attempt you must wait 14 days and buy a new full-price attempt; results typically arrive within 7–10 business days.
The credential is valid for 2 years from the exam date and is renewed by passing an Elastic certification exam before it expires.
Quick Answer: The Elastic Certified SIEM Analyst exam is a timed, cognitive (knowledge-based) exam about the Elastic Security solution, based on Elastic Stack 8.15. It costs $400 USD per attempt, is taken online with remote proctoring, and Elastic's exam page lists a 2-hour duration. The credential is valid for 2 years. Elastic does not publish the number of questions, the passing score or domain weights.
Before studying any feature, know exactly what Elastic measures and how the exam runs. Every fact below comes from Elastic's exam page and Certification FAQ (checked September 2026). Recheck them before you buy an attempt, because Elastic can change prices and policies.
What Kind of Exam Is It?
Elastic runs two styles of certification exam. The Elastic Certified Engineer, Observability Engineer and Analyst exams are performance-based: you complete live tasks on a cluster while a proctor watches. The SIEM Analyst exam is different. It is a timed cognitive-based exam in which you answer:
- Multiple choice questions
- Select all that apply questions
- Fill in the blanks questions
- True or false questions
All of them center on the Elastic Security solution. You will not build a detection rule on a live cluster during the exam. You will be asked which feature, setting, query or workflow achieves a result, and why. That is why this guide stresses exact feature names, defaults, limits and the differences between similar tools.
Exam Facts at a Glance
| Detail | What Elastic Publishes |
|---|---|
| Exam type | Timed cognitive exam: multiple choice, select all that apply, fill in the blanks, true/false |
| Elastic Stack version | 8.15 (Certification FAQ) |
| Duration | 2 hours (listed on the exam page) |
| Fee | $400 USD per attempt; Elastic currently offers no exam discounts; purchases are non-refundable |
| Attempt validity | Use the attempt within one year of purchase (attempts bought through a training subscription expire with the subscription) |
| Prerequisites | None; Elastic strongly encourages the Elastic Security for SIEM course |
| Delivery | Online at any time, remotely proctored with the Honorlock browser extension; scheduled through Trueability |
| Computer | Windows or macOS (Linux is not supported), webcam, microphone, speakers, stable broadband; a 13-inch screen minimum, with a larger screen recommended |
| Identification | Valid, non-expired government-issued photo ID matching your enrollment details |
| Break | One break of up to 10 minutes; it counts toward exam time, and phones are not allowed |
| Documentation | Elastic documentation is available inside the exam environment's browser; all other websites are prohibited |
| Results | Typically within 7–10 business days |
| Retakes | Wait 14 days, then buy a new attempt; reattempts are not discounted |
| Credential | Digital badge issued through Accredible, valid 2 years from the exam date |
| Not published | Number of questions, passing score, domain weights |
Scheduling Rules That Can Cost You an Attempt
- You can reschedule up to 24 hours before your self-scheduled time.
- You must start within 30 minutes of your scheduled time. Otherwise you are marked a no-show and forfeit the attempt.
- If ID verification fails, contact the proctor through Honorlock chat rather than leaving the exam. No refunds or reschedules are given for an invalid or missing ID.
- A US keyboard (or the on-screen keyboard) is recommended for special characters such as
{ }. DeepL translation is available inside the exam environment, and extra time for translation can be requested from certification@elastic.co 3–5 business days in advance.
Keeping the Credential
The certification is valid for 2 years from the exam date. To renew, pass an Elastic certification exam before it expires, which extends an active certification by two years. Extensions are not available for expired certifications.
The Official Exam Objectives
Elastic states that candidates should be able to complete all of the following objectives with only the assistance of the Elastic documentation. The table maps each objective to this guide.
| Objective Group | Elastic's Exam Objectives | Where This Guide Teaches It |
|---|---|---|
| Stack Architecture | Describe basic Stack Architecture; demonstrate use of Fleet and Elastic Agents | Chapter 2; Fleet and Elastic Agent in 3.3 |
| Elastic Common Schema (ECS) | Examine the application and guidelines of ECS | Chapter 3 |
| Discover | Customize the Discover interface to search for data | Chapter 4 |
| Visualizations | Create aggregation-based visualizations for security use cases; construct Lens visualizations for security use cases | Chapters 5 and 6 |
| Dashboards | Construct dashboards for security use cases; demonstrate the use of dashboards | Chapter 7 |
| Security Application | Recognize the capabilities of the Security App; use Explore within the Security App; monitor security-related events with dashboards in the Security App | Chapter 8 |
| Describe how the Detection Engine searches activity and generates alerts | Chapters 9 and 10 | |
| Analyze alerts that are generated from detection rules; correlate relevant data using Timeline | Chapter 11 | |
| Track security issues using Cases; describe how AI is used in the Security App | Chapter 12 |
Two chapters give supporting context. Chapter 13 covers spaces, privileges and Elastic Defend administration, and Chapter 14 follows the threat-hunting capstone that ends Elastic's training course.
Recommended Preparation
Elastic's exam page recommends the Elastic Security for SIEM course, a 24-hour course whose lessons follow the objectives above: Stack overview, ECS, Discover, Visualizations, Dashboards, Security App, and a Hunt capstone. The virtual instructor-led version is listed at $2,700 USD. Elastic also offers an Elastic Security for SIEM Self-Paced Learning Plan. Elastic Training Subscription holders get one exam and one practice exam per solution during the subscription term.
The course assumes a basic understanding of:
- Networking: TCP/IP, common ports and protocols, routers, switches and firewalls
- Network monitoring tools: IDS (Suricata), Zeek and packet capture
- Operating systems: Windows and Linux, file systems and permissions, command-line navigation
- Attack methodology: reconnaissance, command and control (C2) and data exfiltration
A Practical Study Plan
| Week | Focus | Guide Chapters |
|---|---|---|
| 1 | Stack components, Fleet and Elastic Agent, ECS fields and categorization | 2–3 |
| 2 | Discover, KQL and Lucene, ES|QL basics | 4 |
| 3 | Aggregation-based visualizations, Lens and dashboards | 5–7 |
| 4 | Security app tour, Explore pages, Security dashboards, detection engine | 8–9 |
| 5 | Rule types, exceptions, suppression, alert triage and Timeline | 10–11 |
| 6 | Cases, connectors, AI Assistant, privileges, capstone review and practice questions | 12–14 |
Exam-Day Strategy
- Read for the version. The exam targets 8.15, and several features changed later. For example, in 8.15 Attack Discovery is a technical preview and prebuilt rules can't be edited beyond actions and exceptions.
- Watch for "select all that apply." Evaluate every option on its own merits rather than stopping at the first correct one.
- Separate look-alike features. Common traps include exceptions vs. alert suppression, trusted applications vs. event filters, KQL vs. EQL vs. ES|QL syntax, and Cases vs. Timeline.
- Use the documentation deliberately. Know where the Elastic Security docs cover rules, alerts and Timeline, so a lookup takes seconds rather than minutes.
- Budget your time. With 2 hours and an unpublished question count, move on from hard items and come back.
Which Elastic Stack version does Elastic's Certification FAQ list for the Elastic Certified SIEM Analyst exam?
8.8
8.15
9.3
7.17
A candidate fails the Elastic Certified SIEM Analyst exam. According to Elastic's Certification FAQ, what must the candidate do before trying again?
Retake it immediately at a 50% discount within the same week
Wait 14 days and purchase a new exam attempt at the regular price
Wait 90 days and complete the Elastic Security for SIEM course first
Request a free retake from certification@elastic.co within 24 hours
Which of the following details does Elastic NOT publish for the Elastic Certified SIEM Analyst exam? (Select all that apply.)
Select all that apply
The number of questions
The passing score
The price per attempt
The question formats used
During the remotely proctored exam, a candidate takes the permitted break. Which statement matches Elastic's rules?
The break can last up to 30 minutes and pauses the exam clock
The break can last up to 10 minutes, counts toward exam time, and phone use is not permitted
Breaks are not allowed on cognitive exams
The break is unlimited as long as the webcam stays on
Sections you finish are checked off in the contents.