AIF-C01 / Printable Review
Night Before the Exam
A compressed review sheet for AWS Certified AI Practitioner. Use it to refresh decisions, not to learn the exam from scratch.
Domain Weights
| Domain | Weight | Study page |
|---|---|---|
| Fundamentals of AI and ML | 20% | Open Domain 1 |
| Fundamentals of GenAI | 24% | Open Domain 2 |
| Applications of Foundation Models | 28% | Open Domain 3 |
| Guidelines for Responsible AI | 14% | Open Domain 4 |
| Security, Compliance, and Governance for AI Solutions | 14% | Open Domain 5 |
Essential Services
Critical Differences
- Bedrock vs SageMaker AI vs Managed AI Services
- RAG vs Fine-Tuning vs Prompt Engineering
- Secrets Manager vs Parameter Store
Security Concepts
- Roles over long-lived keys where possible.
- Encryption does not replace authorization.
- Resource policies and identity policies can both participate in access decisions.
- CloudTrail answers API activity; Config answers configuration state.
Cost Concepts
- Match capacity model to usage pattern.
- Watch storage access frequency and lifecycle.
- Data transfer and NAT can dominate architecture cost.
- Managed services reduce operations but are not automatically cheapest.
Decision Words
- Least operational overhead: Prefer managed and serverless services when they satisfy the requirement. Exceptions appear when the scenario needs host control, unsupported runtimes, specialized network behavior, or exact migration compatibility.
- Highly available: Identify the failure boundary. One instance is not HA. Multiple instances in one AZ help capacity but not AZ failure. Multi-AZ handles regional AZ faults. Multi-Region handles regional events but adds complexity and cost.
- Durable: Durability is about preserving data. Use replication, versioning, backups, point-in-time recovery, and tested restore plans. A durable backup does not guarantee a low RTO.
- Decouple the application: Use SQS for buffering work, SNS for fanout, EventBridge for event routing, and Step Functions for visible workflow state. Add retries, DLQs, and idempotent consumers.
- Least privilege: Prefer roles and temporary credentials, scope actions/resources/conditions, watch explicit denies, and remember that resource policies may also be required.
- Most cost-effective: Read usage pattern, duration, access frequency, scaling behavior, data transfer, and operations. Cheapest unit price is not always lowest total cost.
- Lowest latency: Move content or compute closer to users, cache aggressively, choose the right database access pattern, and avoid unnecessary cross-Region or NAT paths.
- Private connectivity: Use private subnets, VPC endpoints, PrivateLink, VPN, Direct Connect, Transit Gateway, and tight DNS/routing design instead of public exposure.
- Minimum downtime: Separate deployment downtime, failure recovery, and data restore time. Use blue/green, canary, Multi-AZ, replication, and tested rollback where appropriate.
- Automatic remediation: Pair a reliable signal with EventBridge or CloudWatch, a scoped Systems Manager Automation or Lambda action, and a validation step.
- RPO and RTO: RPO is acceptable data loss. RTO is acceptable recovery time. Backups, replication, failover, and architecture all affect them differently.
- Ordered processing: Use FIFO queues or ordered stream partition keys where ordering really matters. Otherwise preserve throughput and idempotency with standard queues/events.
- Encryption and key management: Encryption protects data confidentiality. KMS key policies and IAM decide who can use keys. Authorization still needs separate design.
- Centralized governance: Use Organizations, SCPs, delegated admin, organization trails, Config aggregators, Security Hub, and account vending for multi-account control.
Common Traps
- Treating generative AI output as authoritative without validation.
- Ignoring the training data and evaluation process when a model is biased or unreliable.
- Choosing model fine-tuning when prompt engineering or retrieval would solve the problem with less overhead.
- Forgetting that customer data and prompts still need governance.
Worth Memorizing
- Fundamentals of AI and ML: 20%
- Fundamentals of GenAI: 24%
- Applications of Foundation Models: 28%
- Guidelines for Responsible AI: 14%
- Security, Compliance, and Governance for AI Solutions: 14%
Understand, Do Not Memorize
- Whether you understand the lifecycle of AI/ML work from data through evaluation and monitoring.
- Whether you can distinguish predictive ML, generative AI, foundation models, embeddings, and retrieval augmented generation.
- Whether you can choose AWS AI services at the right level of abstraction.
- Whether you recognize responsible AI, security, governance, and human-review concerns.
DJames617