Exam Questions With Correct Answers
(Verified Answers) Plus Rationales 2026 Q&A |
Instant Download Pdf
1. What is the primary purpose of Elasticsearch in the Elastic Stack?
A. Data visualization
B. Log shipping
C. Search and analytics engine
D. Alert notification system
Answer: C
Elasticsearch is the core distributed search and analytics engine in the
Elastic Stack. It stores, indexes, and allows fast querying of structured
and unstructured data such as logs and metrics.
2. Which component of the Elastic Stack is primarily used for data
visualization?
A. Logstash
B. Kibana
, C. Beats
D. Elasticsearch
Answer: B
Kibana is the visualization layer of the Elastic Stack. It allows users to
create dashboards, charts, and visual analytics based on data stored
in Elasticsearch.
3. What is the main role of Logstash?
A. Data storage
B. Data processing and transformation
C. Alerting
D. Cluster management
Answer: B
Logstash is a data processing pipeline that ingests, transforms, and
sends data to Elasticsearch or other outputs.
4. Which Beats module is commonly used for system-level metrics?
A. Filebeat
B. Metricbeat
C. Heartbeat
, D. Auditbeat
Answer: B
Metricbeat collects system and service metrics such as CPU usage,
memory, and disk performance and sends them to Elasticsearch.
5. What does Filebeat primarily collect?
A. Network packets
B. Log files
C. CPU metrics
D. Application traces
Answer: B
Filebeat is designed to ship log files from servers or applications to
Elasticsearch or Logstash.
6. What is the purpose of Elasticsearch indices?
A. Store dashboards
B. Store structured documents
C. Manage alerts
D. Process logs
Answer: B
, Indices in Elasticsearch are logical containers that store and organize
documents for efficient querying and retrieval.
7. Which query language is used in Kibana for searching logs?
A. SQL
B. KQL (Kibana Query Language)
C. XPath
D. SPL
Answer: B
KQL is a simple query language used in Kibana to filter and search
data interactively.
8. What is a shard in Elasticsearch?
A. A backup file
B. A type of dashboard
C. A partition of an index
D. A visualization component
Answer: C
A shard is a horizontal partition of an index that helps distribute data
across nodes for scalability and performance.