OpenSearch Log Analysis Quiz

5 questions Pass: 70% +25 pts

Quiz covering Audit and Logging

OpenSearch Log Analysis Quiz

5 questions | Pass: 70% | Earn 25 points

Questions in this quiz

A preview of the 5 questions covered. Start the quiz above to answer them, check your score, and read the explanations.

  1. 1

    Which OpenSearch feature is primarily used to track unauthorized access attempts by recording authentication and authorization events?

  2. 2

    When configuring the OpenSearch audit log, which setting determines the specific categories of events (e.g., 'authenticated', 'rest_request') that are recorded?

  3. 3

    A security analyst needs to ensure that logs are immutable and cannot be deleted by unauthorized users. Which approach is considered a best practice for OpenSearch log governance?

  4. 4

    You notice that the audit logs are filling up disk space too quickly. What is the most efficient way to manage this without losing long-term security visibility?

  5. 5

    When debugging a '403 Forbidden' error in audit logs, you see that the 'origin_address' is logged as '127.0.0.1' despite the request coming from an external client. What is the most likely cause?