SOA-C02 Security and Compliance Practice Question
Network Topology
Refer to the exhibit. A SysOps administrator runs the command to list running EC2 instances. What is the purpose of the '--query' parameter?
⚠ Common exam trap
SOA-C02 often tests the distinction between server-side filtering ('--filters') and client-side output shaping ('--query') — candidates frequently assume '--query' reduces the API payload, when it only reshapes what the CLI prints.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It filters the output to show only specified fields.
The AWS CLI '--query' parameter uses JMESPath to filter and shape the JSON response returned by the API call, so it controls which fields appear in the output. It does not change what the API returns from the server; it only transforms the client-side presentation. This is why it is described as filtering the output to show only specified fields.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It filters the results on the server side.
Why it's wrong here
The AWS CLI's --query parameter does not perform server-side filtering; that capability belongs to the --filters option, which translates into EC2 API request parameters so AWS returns only matching resources. In contrast, --query executes a JMESPath expression locally on the entire JSON response already received by the CLI. Therefore, this option incorrectly assigns server-side behavior to a purely client-side operation.
- ✗
It limits the API call to only running instances.
Why it's wrong here
Using --query never alters the underlying DescribeInstances API call, which will still retrieve the complete list of instances (subject to pagination) without any instance-state filter. The JMESPath expression runs after the full response has been downloaded and can only select or shape fields from that complete data set. Thus it cannot limit the API call to running instances; that would require passing e.g. --filters "Name=instance-state-name,Values=running" as a request parameter.
- ✓
It filters the output to show only specified fields.
Why this is correct
The --query parameter in this command takes a JMESPath expression that processes the JSON response and extracts only the fields the user wants to display, such as instance IDs and their state. It filters the output client-side after the API returns the data, thereby customizing the visible result without changing the underlying API request. This is the correct interpretation of what the command accomplishes.
- ✗
It saves the output to a file.
Why it's wrong here
Redirecting output to a file is a function of the shell, not of the AWS CLI's --query parameter; for example, appending `> instances.txt` to the command saves the stdout to a file. The --query parameter simply transforms the JSON result and prints it to standard output. Unless an output redirection operator or the --output and --no-cli-pager settings are used with a file destination, the results appear only on screen.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.