SC-200 Manage a security operations environment Practice Question
Exhibit
Refer to the exhibit. ```powershell PS C:\> Get-MpComputerStatus | Select-Object AMProductVersion, AMServiceEnabled, AntivirusEnabled, RealTimeProtectionEnabled AMProductVersion AMServiceEnabled AntivirusEnabled RealTimeProtectionEnabled --------------- ----------------- ---------------- ----------------------- 4.18.2304.9 True True False ```
Refer to the exhibit. You are troubleshooting an endpoint that is not receiving real-time protection from Microsoft Defender Antivirus. The output shows RealTimeProtectionEnabled is False. Which command should you run next to enable real-time protection?
⚠ Common exam trap
Many exam-takers confuse disabling real-time monitoring with other maintenance tasks like scanning or updating signatures, assuming any Defender-related command will fix the protection state, but only Set-MpPreference directly controls the RealTimeProtectionEnabled flag.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set-MpPreference -DisableRealtimeMonitoring $false
The Set-MpPreference cmdlet with the -DisableRealtimeMonitoring $false parameter is the correct command to enable real-time protection in Microsoft Defender Antivirus. The output shows RealTimeProtectionEnabled is False, which directly corresponds to the DisableRealtimeMonitoring setting; setting it to $false re-enables the feature. This cmdlet modifies the local policy for the Microsoft Defender Antivirus engine, immediately activating real-time scanning of file operations and process activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Set-MpPreference -DisableRealtimeMonitoring $false
Why this is correct
Set-MpPreference -DisableRealtimeMonitoring $false is the correct command because it explicitly sets the DisableRealtimeMonitoring configuration to false, which re-enables Microsoft Defender's real-time scanning engine. This preference is the direct control for the monitoring state, and applying it reverses any setting that previously disabled the service. It is the only option that addresses the root cause of a disabled real-time protection rather than performing an unrelated action.
- ✗
Add-MpPreference -ExclusionPath C:\Temp
Why it's wrong here
Add-MpPreference -ExclusionPath C:\Temp is incorrect because it only adds a folder to the Defender exclusion list, instructing the antivirus to ignore that directory. This action does not touch the DisableRealtimeMonitoring registry or policy setting, so real-time monitoring remains disabled. Moreover, adding an exclusion could actually widen the attack surface for files in C:\Temp while doing nothing to restore proactive protection.
- ✗
Start-MpScan
Why it's wrong here
Start-MpScan is a one-time command that launches an on-demand scan of the endpoint immediately. While this can find malware that is already present, it does not enable real-time monitoring, so the always-on protection stays inactive after the scan concludes. The endpoint would remain vulnerable to new files and behaviors that appear after the scan, making this a temporary reactive measure rather than a fix for the disabled monitoring state.
- ✗
Update-MpSignature
Why it's wrong here
Update-MpSignature downloads the latest antivirus definitions into the signature store but does not affect the real-time monitoring engine's configuration. Even with brand-new signatures, Microsoft Defender will still not scan files automatically if real-time protection is disabled, because the signature update only refreshes threat intelligence data. This cmdlet is useful for keeping definitions current, but it cannot re-enable a service that has been turned off.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.