SMEX performs real-time scan messages as they are accessed. It is performed if the message has not been previously scanned using the latest pattern file and scan engine.
This feature is also known as on-access scan which is only available when SMEX is running on Microsoft Exchange Server 2007 or 2010. Since Exchange 2013, Microsoft excludes Virus Scan API (VSAPI) that does not allow security vendor to perform real-time scan on mail store level.
For detailed information, see Chapter 1.1 in ScanMail for Exchange (SMEX) 12.0 Service Pack 1 (SP1) Best Practice Guide.
In Microsoft Exchange 2013 and 2016, there is no Real-time Scan Settings on SMEX web console under the Administration section. The on-access feature is no longer available on these platforms.
The primary protection is to enable real-time scan on the transport level. To know the recommended scan settings for different server roles, see Chapter 4.1.1 in ScanMail for Exchange (SMEX) 12.0 Service Pack 1 (SP1) Best Practice Guide.
Trend Micro also recommends configuring manual and scheduled mailbox database scan to minimize the chance of infection.