Courseiva

MS-102 Practice Question: Manage security and threats by using Microsoft Defender XDR

Exhibit

Refer to the exhibit.

```powershell
Get-MpPreference | Select-Object -Property DisableRealtimeMonitoring, DisableBehaviorMonitoring, DisableBlockAtFirstSeen
```

Output:
```
DisableRealtimeMonitoring : False
DisableBehaviorMonitoring : True
DisableBlockAtFirstSeen : False
```

You run the above PowerShell command on a Windows 10 device that is onboarded to Microsoft Defender for Endpoint. The device is reporting as healthy in the portal, but you suspect that some behavioral detection capabilities are turned off. Based on the output, which setting should you modify?

⚠ Common exam trap

Watch out — candidates often confuse 'behavior monitoring' with 'real-time monitoring' or 'cloud-delivered protection,' leading them to select options that address unrelated security features instead of the specific setting shown in the PowerShell output.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set DisableBehaviorMonitoring to False to enable behavior monitoring.

The PowerShell command output shows that DisableBehaviorMonitoring is set to True, which disables behavioral monitoring. Since the device is healthy but behavioral detection capabilities are suspected to be off, setting DisableBehaviorMonitoring to False re-enables behavior monitoring, allowing Defender for Endpoint to analyze runtime behavior for threats.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Set DisableBehaviorMonitoring to False to enable behavior monitoring.

    Why this is correct

    The existing output lists `DisableBehaviorMonitoring : True`, and because `Set-MpPreference` uses Boolean settings where `True` disables the corresponding feature, behavior monitoring is currently off. Running `Set-MpPreference -DisableBehaviorMonitoring $false` changes that value to `False`, turning on behavior monitoring. This Defender engine feature inspects process behavior, memory access, and system activity to detect fileless attacks and post-breach behaviors that static signature scanning may miss.

  • ✗

    Enable cloud-delivered protection by setting MAPSReporting to Advanced.

    Why it's wrong here

    Cloud-delivered protection is controlled by the `MAPSReporting` parameter, which accepts values like `Disabled`, `Basic`, or `Advanced`; however, the output shown does not include `MAPSReporting`, so you cannot infer its current state from this command. More importantly, changing `MAPSReporting` only adjusts your membership level in the Microsoft Active Protection Service and does not enable behavior monitoring, which is the issue the output indicates. Cloud-delivered protection is also a separate Defender layer from the local behavior monitoring engine.

  • ✗

    Set DisableBlockAtFirstSeen to True to enable Block at First Sight.

    Why it's wrong here

    The `DisableBlockAtFirstSeen` value of `False` already means Block at First Sight is enabled, because this parameter is named as a disable switch: `True` would disable the feature, while `False` enables it. Setting this value to `True`, as proposed, would actually turn off Block at First Sight, directly contradicting the goal of enabling a protection feature. Block at First Sight is also a cloud-delivered capability that requires MAPS membership, so it is unrelated to the behavior monitoring setting that needs correction.

  • ✗

    Set DisableRealtimeMonitoring to True to enable real-time monitoring.

    Why it's wrong here

    `DisableRealtimeMonitoring` is currently `False`, which indicates real-time monitoring is already active, because `True` is the value that would disable it. Running `Set-MpPreference -DisableRealtimeMonitoring $true` would therefore stop real-time protection, worsening the device's security posture rather than fixing the behavior monitoring gap. While real-time monitoring and behavior monitoring are complementary Defender components, they are controlled by separate registry-backed policies and PowerShell parameters, so changing one does not affect the other.

About these practice questions

This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.