Courseiva

SC-200 Manage a security operations environment Practice Question

Exhibit

Refer to the exhibit.
```powershell
PS C:\> Get-MpComputerStatus | Select-Object AMProductVersion, AMServiceEnabled, AntivirusEnabled, RealTimeProtectionEnabled

AMProductVersion AMServiceEnabled AntivirusEnabled RealTimeProtectionEnabled
--------------- ----------------- ---------------- -----------------------
4.18.2304.9     True              True             False
```

Refer to the exhibit. You are troubleshooting an endpoint that is not receiving real-time protection from Microsoft Defender Antivirus. The output shows RealTimeProtectionEnabled is False. Which command should you run next to enable real-time protection?

⚠ Common exam trap

Many exam-takers confuse disabling real-time monitoring with other maintenance tasks like scanning or updating signatures, assuming any Defender-related command will fix the protection state, but only Set-MpPreference directly controls the RealTimeProtectionEnabled flag.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set-MpPreference -DisableRealtimeMonitoring $false

The Set-MpPreference cmdlet with the -DisableRealtimeMonitoring $false parameter is the correct command to enable real-time protection in Microsoft Defender Antivirus. The output shows RealTimeProtectionEnabled is False, which directly corresponds to the DisableRealtimeMonitoring setting; setting it to $false re-enables the feature. This cmdlet modifies the local policy for the Microsoft Defender Antivirus engine, immediately activating real-time scanning of file operations and process activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Set-MpPreference -DisableRealtimeMonitoring $false

    Why this is correct

    Set-MpPreference -DisableRealtimeMonitoring $false is the correct command because it explicitly sets the DisableRealtimeMonitoring configuration to false, which re-enables Microsoft Defender's real-time scanning engine. This preference is the direct control for the monitoring state, and applying it reverses any setting that previously disabled the service. It is the only option that addresses the root cause of a disabled real-time protection rather than performing an unrelated action.

  • ✗

    Add-MpPreference -ExclusionPath C:\Temp

    Why it's wrong here

    Add-MpPreference -ExclusionPath C:\Temp is incorrect because it only adds a folder to the Defender exclusion list, instructing the antivirus to ignore that directory. This action does not touch the DisableRealtimeMonitoring registry or policy setting, so real-time monitoring remains disabled. Moreover, adding an exclusion could actually widen the attack surface for files in C:\Temp while doing nothing to restore proactive protection.

  • ✗

    Start-MpScan

    Why it's wrong here

    Start-MpScan is a one-time command that launches an on-demand scan of the endpoint immediately. While this can find malware that is already present, it does not enable real-time monitoring, so the always-on protection stays inactive after the scan concludes. The endpoint would remain vulnerable to new files and behaviors that appear after the scan, making this a temporary reactive measure rather than a fix for the disabled monitoring state.

  • ✗

    Update-MpSignature

    Why it's wrong here

    Update-MpSignature downloads the latest antivirus definitions into the signature store but does not affect the real-time monitoring engine's configuration. Even with brand-new signatures, Microsoft Defender will still not scan files automatically if real-time protection is disabled, because the signature update only refreshes threat intelligence data. This cmdlet is useful for keeping definitions current, but it cannot re-enable a service that has been turned off.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.