nerdexam
Cisco

300-215 · Question #10

Refer to the exhibit. An HR department submitted a ticket to the IT helpdesk indicating slow performance on an internal share server. The helpdesk engineer checked the server with a real- time…

The correct answer is A. unauthorized system modification E. malware outbreak. According to the event log, a suspicious service was installed (DIAOHHNMPMMRgji) with a service file pointing to a remote share (\\127.0.0.1\admin$\EqnBqKWm.exe). This type of activity strongly suggests: Unauthorized system modification: Installation of a service without proper…

Submitted by saadiq_pk· Mar 6, 2026Cloud Security Operations & Incident Response

Question

Refer to the exhibit. An HR department submitted a ticket to the IT helpdesk indicating slow performance on an internal share server. The helpdesk engineer checked the server with a real- time monitoring tool and did not notice anything suspicious. After checking the event logs, the engineer noticed an event that occurred 48 hour prior. Which two indicators of compromise should be determined from this information? (Choose two.)

Exhibit

300-215 question #10 exhibit

Options

  • Aunauthorized system modification
  • Bprivilege escalation
  • Cdenial of service attack
  • Dcompromised root access
  • Emalware outbreak

How the community answered

(36 responses)
  • A
    58% (21)
  • B
    11% (4)
  • C
    25% (9)
  • D
    6% (2)

Explanation

According to the event log, a suspicious service was installed (DIAOHHNMPMMRgji) with a service file pointing to a remote share (\127.0.0.1\admin$\EqnBqKWm.exe). This type of activity strongly suggests: Unauthorized system modification: Installation of a service without proper authorization, especially with a random or obfuscated name, directly fits the description of system modification. The use of admin$ (administrative share) further implies this wasn't part of standard operations. Malware outbreak: The use of a service that points to an executable with a seemingly random name and the demand start configuration indicate a potential backdoor or remote-controlled As stated in the Cisco CyberOps Associate guide, event ID 7045 with unusual service names or file paths is a strong Indicator of Compromise (IoC) for malware or persistence mechanisms. Options like privilege escalation or DoS are not directly evidenced in the event log shown. There's no indication that the LocalSystem account was elevated beyond its default, nor that system resources were overwhelmed (as would be typical in DoS).

Topics

#Indicators of Compromise#Incident investigation#Log analysis#Malware outbreak

Community Discussion

No community discussion yet for this question.

Full 300-215 Practice