easyMultiple Choice
MD-102 Practice Question: Deploying Microsoft Defender for Endpoint to…
You are deploying Microsoft Defender for Endpoint to Windows 10 devices managed by Microsoft Intune. After onboarding, you need to verify that the sensor is running. Which cmdlet should you use on the device?
⚠ Common exam trap
Test-takers frequently confuse the Defender for Endpoint sensor service (Sense) with the Windows Defender Antivirus service (WinDefend) or mistakenly use a non-existent cmdlet like Get-DefenderEndpoint, leading them to choose an incorrect verification method.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Get-Service -Name Sense
The correct cmdlet is Get-Service -Name Sense because the Microsoft Defender for Endpoint sensor runs as a Windows service named 'Sense' (Microsoft Defender Advanced Threat Protection Service). Checking this service confirms the sensor is installed and running, which is the standard verification step after onboarding devices to Defender for Endpoint.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Get-Service -Name WinDefend
Why it's wrong here
Get-Service -Name WinDefend reports the Windows Defender Antivirus service, not the Defender for Endpoint sensor, which runs as Sense. It is tempting because WinDefend genuinely indicates antivirus health, and checking it would be valid when verifying Defender Antivirus status rather than onboarding sensor state.
- ✗
Get-DefenderEndpoint
Why it's wrong here
Get-DefenderEndpoint is not a real cmdlet, so it returns a command-not-found error and cannot report sensor state; it is tempting because its name sounds like the Defender counterpart to Get-MpComputerStatus, but no such cmdlet exists in the Defender for Endpoint module.
- ✗
Get-MpComputerStatus
Why it's wrong here
Get-MpComputerStatus reports Microsoft Defender Antivirus health, including AMServiceEnabled and RealTimeProtectionEnabled, not the Defender for Endpoint onboarding sensor state; it is tempting because it confirms antivirus is running, but verifying the EDR sensor requires Get-MpComputerStatus's sibling, the Sense service status.
- ✓
Get-Service -Name Sense
Why this is correct
Get-Service -Name Sense queries the Sense service, which hosts the Microsoft Defender for Endpoint sensor on Windows 10. Checking its Status confirms the sensor is running, directly satisfying the stem's verification requirement after Intune onboarding. Other cmdlets inspect configuration or events rather than live service state.
Go deeper
Related to this question
Learn chapter
Managing Microsoft 365 Apps and Office Updates
Key term
Windows 10
Windows 10 is a personal computer operating system developed by Microsoft that combines the familiarity of Windows 7 with the modern features of Windows 8, designed to run on a wide range of devices from desktops to tablets.
Key term
Microsoft Intune
Microsoft Intune is a cloud-based service that helps organizations manage employee devices, apps, and security policies without needing to own or control the physical hardware.
About these practice questions
Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.