AIF-C01 / Printable Review

Night Before the Exam

A compressed review sheet for AWS Certified AI Practitioner. Use it to refresh decisions, not to learn the exam from scratch.

Timed Practice Check

Domain Weights

AIF-C01 exam blueprint
DomainWeightStudy page
Fundamentals of AI and ML20%Open Domain 1
Fundamentals of GenAI24%Open Domain 2
Applications of Foundation Models28%Open Domain 3
Guidelines for Responsible AI14%Open Domain 4
Security, Compliance, and Governance for AI Solutions14%Open Domain 5

Essential Services

Critical Differences

  • Bedrock vs SageMaker AI vs Managed AI Services
  • RAG vs Fine-Tuning vs Prompt Engineering
  • Secrets Manager vs Parameter Store

Security Concepts

  • Roles over long-lived keys where possible.
  • Encryption does not replace authorization.
  • Resource policies and identity policies can both participate in access decisions.
  • CloudTrail answers API activity; Config answers configuration state.

Cost Concepts

  • Match capacity model to usage pattern.
  • Watch storage access frequency and lifecycle.
  • Data transfer and NAT can dominate architecture cost.
  • Managed services reduce operations but are not automatically cheapest.

Decision Words

  • Least operational overhead: Prefer managed and serverless services when they satisfy the requirement. Exceptions appear when the scenario needs host control, unsupported runtimes, specialized network behavior, or exact migration compatibility.
  • Highly available: Identify the failure boundary. One instance is not HA. Multiple instances in one AZ help capacity but not AZ failure. Multi-AZ handles regional AZ faults. Multi-Region handles regional events but adds complexity and cost.
  • Durable: Durability is about preserving data. Use replication, versioning, backups, point-in-time recovery, and tested restore plans. A durable backup does not guarantee a low RTO.
  • Decouple the application: Use SQS for buffering work, SNS for fanout, EventBridge for event routing, and Step Functions for visible workflow state. Add retries, DLQs, and idempotent consumers.
  • Least privilege: Prefer roles and temporary credentials, scope actions/resources/conditions, watch explicit denies, and remember that resource policies may also be required.
  • Most cost-effective: Read usage pattern, duration, access frequency, scaling behavior, data transfer, and operations. Cheapest unit price is not always lowest total cost.
  • Lowest latency: Move content or compute closer to users, cache aggressively, choose the right database access pattern, and avoid unnecessary cross-Region or NAT paths.
  • Private connectivity: Use private subnets, VPC endpoints, PrivateLink, VPN, Direct Connect, Transit Gateway, and tight DNS/routing design instead of public exposure.
  • Minimum downtime: Separate deployment downtime, failure recovery, and data restore time. Use blue/green, canary, Multi-AZ, replication, and tested rollback where appropriate.
  • Automatic remediation: Pair a reliable signal with EventBridge or CloudWatch, a scoped Systems Manager Automation or Lambda action, and a validation step.
  • RPO and RTO: RPO is acceptable data loss. RTO is acceptable recovery time. Backups, replication, failover, and architecture all affect them differently.
  • Ordered processing: Use FIFO queues or ordered stream partition keys where ordering really matters. Otherwise preserve throughput and idempotency with standard queues/events.
  • Encryption and key management: Encryption protects data confidentiality. KMS key policies and IAM decide who can use keys. Authorization still needs separate design.
  • Centralized governance: Use Organizations, SCPs, delegated admin, organization trails, Config aggregators, Security Hub, and account vending for multi-account control.

Common Traps

  • Treating generative AI output as authoritative without validation.
  • Ignoring the training data and evaluation process when a model is biased or unreliable.
  • Choosing model fine-tuning when prompt engineering or retrieval would solve the problem with less overhead.
  • Forgetting that customer data and prompts still need governance.

Worth Memorizing

  • Fundamentals of AI and ML: 20%
  • Fundamentals of GenAI: 24%
  • Applications of Foundation Models: 28%
  • Guidelines for Responsible AI: 14%
  • Security, Compliance, and Governance for AI Solutions: 14%

Understand, Do Not Memorize

  • Whether you understand the lifecycle of AI/ML work from data through evaluation and monitoring.
  • Whether you can distinguish predictive ML, generative AI, foundation models, embeddings, and retrieval augmented generation.
  • Whether you can choose AWS AI services at the right level of abstraction.
  • Whether you recognize responsible AI, security, governance, and human-review concerns.

Sources and Review Metadata

This independent training application is not affiliated with or endorsed by Amazon Web Services. AWS, Amazon Web Services, and AWS certification names are trademarks of Amazon.com, Inc. or its affiliates.