Free online certification
Free Elasticsearch Certification Exam
The BigData Boutique Elasticsearch certification is a free online exam: 20 questions in 15 minutes, with a pass mark of 75%. It covers core concepts, indexing, Query DSL and ES|QL, cluster operations and security, and every question is checked against the official Elastic documentation. Pass and you get a verifiable certificate you can add to LinkedIn.
Free exam and certificate. No account needed to start. Last updated .
Elasticsearch certification exam facts
| Price | Free: the exam, the results breakdown and the certificate |
|---|---|
| Format | Online, in your browser. Multiple choice; some questions have more than one correct answer |
| Questions | 20 per attempt |
| Time limit | 15 minutes |
| Pass mark | 75% |
| Based on | The official Elastic documentation (current release); every question cites its source page |
| Also relevant to | Elastic Cloud and self-managed ELK Stack deployments |
| Proctoring | None. No webcam, no software to install and no account needed to start |
| Retakes | Free and unlimited; each attempt draws a different set of questions |
| Validity | No expiry; the certificate shows its issue date |
| Certificate | Unique verification link on bigdataboutique.com and one-click Add to LinkedIn |
| Issued by | BigData Boutique |
What to expect
What the Elasticsearch exam covers
Each attempt includes questions from every topic below. Some questions have more than one correct answer.
-
Core Concepts
nodes, indices, shards, replicas, the cluster state and how Elasticsearch fits into the Elastic Stack
-
Indexing & Mappings
field types, analyzers, index templates, data streams, aliases and the Bulk and Reindex APIs
-
Query DSL & Search
match, term and bool queries, aggregations, relevance, ES|QL and vector search
-
Operations & Cluster
shard allocation, ILM, snapshots, upgrades, monitoring and capacity planning
-
Security & Elastic Stack
roles and API keys, TLS, Kibana, Logstash and Beats
How the certification works
Take the online test in your browser. Pass to earn your certificate, then add it to LinkedIn or share your achievement on social media.
Who it's for
Engineers, SREs and architects working with Elasticsearch or Elastic Cloud. It's also a useful way to check your knowledge before an interview or find topics to study next.
Preparing for the exam? Review the official Elasticsearch documentation, which is referenced by the exam questions.
Practice test
Elasticsearch practice questions
These sample questions are in the style of the exam and are not part of its question pool. Try each one, then open the answer to check yourself against the documentation.
-
Which of these index settings can only be set when the index is created?
- index.number_of_replicas
- index.number_of_shards
- index.refresh_interval
- index.max_result_window
Show answer
index.number_of_shards. The number of primary shards is fixed when the index is created. Changing it means reindexing, or using the shrink or split APIs. The other three settings can be updated on a live index. Read the documentation.
-
In a bool query, which clause requires documents to match but does not contribute to the relevance score?
- must
- should
- filter
- minimum_should_match
Show answer
filter. Clauses under filter run in filter context: documents must match, but scoring is ignored and the clause can be cached. Read the documentation.
-
Which Elasticsearch feature automates rollover, moving indices between data tiers and deleting old indices based on policies?
- Index State Management (ISM)
- Index lifecycle management (ILM)
- Cross-cluster replication
- Snapshot lifecycle management (SLM)
Show answer
Index lifecycle management (ILM). Index lifecycle management (ILM) moves indices through hot, warm, cold, frozen and delete phases. ISM is the OpenSearch feature with a similar purpose, and SLM schedules snapshots. Read the documentation.
-
Which Elasticsearch query language chains processing commands with the pipe character, for example FROM logs | WHERE status == 500 | STATS count = COUNT(*)?
- Query DSL
- KQL
- EQL
- ES|QL
Show answer
ES|QL. ES|QL is a piped query language: a source command such as FROM is followed by processing commands separated by pipes. Read the documentation.
-
What is the cluster health status when every primary shard is assigned but at least one replica shard is not?
- Green
- Yellow
- Red
Show answer
Yellow. Yellow means all primary shards are assigned and the data is searchable, but one or more replicas are unassigned. Red means at least one primary shard is unassigned. Read the documentation.
Ready for the timed Elasticsearch exam?
Start the examOfficial Elastic certifications compared
Elastic offers four official certifications. They cost $400 to $500 per attempt, are proctored over audio and video, and are valid for two years. Three are performance-based, meaning you complete tasks in real time; the SIEM Analyst exam uses multiple-choice style questions. This free exam is independent of Elastic and works as a first step or a practice test before you pay for an official attempt.
| Certification | Cost | Format | Tested on | Focus |
|---|---|---|---|---|
| Elasticsearch Certification (this exam) | Free | Online, multiple choice, unproctored | Current Elastic documentation | Elasticsearch concepts, indexing, search, operations and security |
| Elastic Certified Engineer | $500 per attempt | Performance-based, proctored | Version 9.3 | Indexing, searching and managing data in Elasticsearch |
| Elastic Certified Observability Engineer | $500 per attempt | Performance-based, proctored | Version 8.8 | Setting up and monitoring an observable system with the Elastic Stack |
| Elastic Certified Analyst | $400 per attempt | Performance-based, proctored | Version 8.8 | Data visualization and analysis in Kibana |
| Elastic Certified SIEM Analyst | $400 per attempt | Multiple choice, select all that apply, fill in the blanks and true or false; proctored | Version 8.15 | SIEM analysis with Elastic Security |
Official certifications are valid for two years from the exam date. If you do not pass, Elastic requires a 14-day wait and a new purchase before the next attempt. Prices and versions are as listed in Elastic's certification FAQ on the date this page was last updated.
Sources: Elastic certification, Elastic certification FAQ.
How to prepare for the Elasticsearch certification exam
Take the exam once to get a baseline, study the topics where you scored lowest, then retake it. These resources cover what the questions test.
-
Official Elastic documentation
The source for every exam question. Focus on mappings, Query DSL, ES|QL, ILM and cluster administration.
-
OpenSearch vs Elasticsearch compared
Where the two engines differ, useful if you work with both.
-
Free OpenSearch certification
The sister exam, if you also run OpenSearch.
Elasticsearch certification FAQ
Is there a free Elasticsearch certification?
Yes. The BigData Boutique Elasticsearch certification is free: the exam, the topic-by-topic results and the certificate cost nothing. You answer 20 questions in 15 minutes in your browser, and a score of 75% or more earns a verifiable certificate for LinkedIn. Elastic's own official certification exams are paid.
Is this the official Elastic Certified Engineer exam?
No. This is an independent certification by BigData Boutique and is not affiliated with or endorsed by Elastic. The Elastic Certified Engineer exam is Elastic's own performance-based, proctored exam and costs $500 per attempt. Many engineers use this free exam to check their knowledge before paying for the official one.
How much does Elastic certification cost?
Elastic lists the Elastic Certified Engineer and Elastic Certified Observability Engineer exams at $500 per attempt, and the Elastic Certified Analyst and Elastic Certified SIEM Analyst exams at $400 per attempt. Exam purchases are not refundable and must be used within one year. The BigData Boutique Elasticsearch certification is free.
Which Elastic certification should I take first?
Most Elasticsearch practitioners start with the Elastic Certified Engineer, which covers indexing, searching and managing data. Pick the Analyst exam if you work mainly in Kibana, the Observability Engineer exam for monitoring, or the SIEM Analyst exam for Elastic Security. A free exam like this one is a low-risk way to gauge readiness first.
How hard is the Elastic Certified Engineer exam?
It is performance-based: you complete real tasks in real time rather than answering multiple-choice questions, and a proctor monitors you over audio and video. You may use the Elastic documentation but no other websites. Elastic's FAQ does not publish a pass rate or passing score, so hands-on practice matters more than memorization.
Do Elastic certifications expire?
Yes. Elastic certifications are valid for two years from the exam date. To recertify you take and pass any of the Elastic certification exams, which extends an active certification by two years. The BigData Boutique certificate does not expire; it shows the date you passed and the score you achieved.
Are there Elasticsearch certification dumps?
Avoid them. Elastic prohibits reproducing or distributing exam content, and violations can lead to revoked certifications and bans ranging from six months to a lifetime. Dumps also do not help with a performance-based exam. Use legitimate practice instead: this free exam asks documentation-backed questions and shows which topics you need to study.
Is there an ELK Stack certification?
There is no exam named ELK certification. ELK Stack skills, meaning Elasticsearch, Logstash and Kibana, are certified through Elastic's four exams; Elastic describes the Observability Engineer certification as being for ELK Stack experts who can set up and monitor an observable system. This free exam covers Elasticsearch, the core of the stack.
What topics does the Elasticsearch certification exam cover?
Five topics, with questions from each in every attempt: core concepts such as nodes, shards and replicas; indexing and mappings, including data streams; Query DSL and search, including aggregations and ES|QL; operations and cluster management, including ILM and snapshots; and security and the Elastic Stack, including roles, TLS and Kibana.
Can I use this exam as an Elasticsearch practice test or for sample questions?
Yes. Every attempt draws 20 questions from a larger question bank and shuffles the answers, so you can retake it as often as you like. You get a score and a breakdown by topic each time, and this page lists sample questions with explained answers and links to the documentation.
Can I pass with OpenSearch experience?
Much of it carries over. OpenSearch was forked from Elasticsearch 7.10, so core concepts such as shards, mappings, analyzers and Query DSL are shared. Features added to Elasticsearch since then, such as ES|QL, differ, and lifecycle management is ILM rather than ISM. Review those areas first, or take the free OpenSearch certification instead.
Who issues the certificate, and how can it be verified?
BigData Boutique, a consultancy that runs Elasticsearch and OpenSearch in production for its customers, issues this certification. Each certificate has a unique verification link on bigdataboutique.com that shows the holder's name, score and issue date, and an Add to LinkedIn button that fills in the details for you.
Is this exam useful for Elasticsearch interview preparation?
Yes. The questions cover what Elasticsearch interviews usually probe: shards and replicas, mappings and analyzers, query types, aggregations, cluster health and security. Take the exam, review the topics where you scored lowest, and read the cited documentation pages for those areas before your interview.
Ready to test your knowledge?
Start the examElasticsearch, Kibana, Logstash and Elastic are trademarks of Elasticsearch B.V. This is an independent certification by BigData Boutique; it is not affiliated with, issued by or endorsed by Elastic.
Working with Elasticsearch in production?
Talk to our engineers about Elasticsearch consulting, migrations or production support.
Elasticsearch consulting · Elasticsearch enterprise support · Elasticsearch to OpenSearch migration