AWS Certified Generative AI Developer – Professional Cheat Sheet (AIP-C01)
Every Bedrock feature, RAG and agent pattern, and safety / observability decision the AIP-C01 exam actually tests — organised by the five exam domains with reference architectures and runbooks
About This Cheat Sheet
A 14-page professional-tier reference covering every in-scope service from the official AIP-C01 exam guide, organised around the five exam domains: Foundation Model Integration, Data Management & Compliance (31%), Implementation & Integration (26%), AI Safety, Security & Governance (20%), Operational Efficiency & Optimization (12%), Testing, Validation & Troubleshooting (11%). Structured for candidates with 2+ years of AWS development and prior AI/ML experience — sections move from GenAI vocabulary and the customisation ladder (prompt engineering → RAG → fine-tuning → continued pre-training → train from scratch) through Amazon Bedrock (model providers Amazon Nova + Titan, Anthropic Claude, Meta Llama, Mistral, Cohere, AI21, Stability; inference modes including On-Demand, Provisioned Throughput, Batch Inference, Cross-Region Inference, Latency-Optimized Inference; Playgrounds, Model Evaluation, Guardrails with content + denied-topic + sensitive-info + contextual-grounding + prompt-injection filters, Custom Models, Bedrock Studio), Bedrock Knowledge Bases (managed RAG, supported vector stores, RetrieveAndGenerate vs Retrieve, Bedrock Data Automation, reranking), Bedrock Prompt Management + Prompt Flows, Bedrock Agents + Bedrock AgentCore (Runtime / Gateway / Memory / Identity / Observability / Code Interpreter / Browser tool) + Strands Agents + Agent Squad + Amazon Augmented AI, vector stores and retrieval architectures (OpenSearch Serverless with Neural plugin, Aurora pgvector, Neptune Analytics for GraphRAG, DocumentDB, MemoryDB / ElastiCache, DynamoDB) with chunking + embedding + hybrid search + query transformation patterns, the complete Amazon SageMaker AI suite (Unified Studio, JumpStart, Data Wrangler, Ground Truth, Clarify, Model Monitor, Model Registry, Processing, Neo), AWS AI services and Amazon Q (Comprehend, Kendra, Lex, Rekognition, Textract, Transcribe, Q Business + Q Business Apps, Q Developer, Connect), compute (Lambda + Lambda@Edge, App Runner, EC2 with p5/trn/inf/g-series + Capacity Blocks, ECS/EKS/Fargate/ECR, Outposts + Wavelength), storage (S3 with Intelligent-Tiering + Lifecycle + Cross-Region Replication, EBS, EFS, DataSync, Transfer Family, Glue, EMR, Kinesis, MSK, Athena, QuickSight), databases for GenAI (Aurora pgvector, RDS, DynamoDB + Streams, DocumentDB, ElastiCache, Neptune, OpenSearch Service), application integration (EventBridge, Step Functions, SNS, SQS, AppFlow, AppConfig, Chatbot), API and edge (API Gateway, AppSync, CloudFront, Global Accelerator, PrivateLink, ELB, Route 53, Amplify), security (IAM, IAM Access Analyzer, IAM Identity Center, Cognito, KMS, AWS Encryption SDK, Secrets Manager, Macie, WAF) with responsible-AI controls, observability (CloudWatch + CloudWatch Logs + CloudWatch Synthetics, X-Ray, CloudTrail, Managed Grafana, Systems Manager, Service Catalog, Auto Scaling, Well-Architected Tool GenAI lens, Cost Anomaly Detection + Cost Explorer), DevOps (CDK, CloudFormation, CodePipeline + CodeBuild + CodeDeploy + CodeArtifact, CLI + Tools + SDKs), testing + eval + metrics (Bedrock Model Evaluation automatic + human, Clarify FM evaluation, RAGAS-style RAG metrics, BLEU / ROUGE / METEOR / BERTScore, perplexity), five reference architectures (document-grounded chatbot, agentic assistant with internal tools, fine-tuned domain model, multimodal intake pipeline, Amazon Q Business deployment), 23-scenario answer patterns, 10 common pitfalls, a prompt-engineering deep dive (foundational + reasoning + structural patterns, inference parameter settings), a responsible-AI checklist, a cost-control playbook, multi-Region + resilience, and four operational runbooks (latency regression, prompt-injection incident, KB data drift, agent cost runaway). Every service on the AIP-C01 in-scope list is audited present.
What's Inside
GenAI Vocabulary & Customisation Ladder
Foundation models, LLMs vs multimodal, embeddings, tokens + context window, inference parameters (temperature, top-p, top-k, max_tokens, stop sequences, frequency + presence penalty), RAG, agents, Model Context Protocol (MCP). Customisation ladder: prompt engineering → RAG → fine-tuning → continued pre-training → train from scratch with cost and applicability guidance.
Amazon Bedrock Core
Model providers (Amazon Nova + Titan; Anthropic Claude Haiku/Sonnet/Opus; Meta Llama 3.x; Mistral Small/Large; Cohere Command R/R+ + Embed + Rerank; AI21 Jamba; Stability SD 3.x). Inference modes: On-Demand, Provisioned Throughput, Batch Inference (~50% cheaper), Cross-Region Inference, Latency-Optimized Inference. Bedrock Playgrounds, Model Evaluation (automatic + human), Guardrails (content filters + denied topics + sensitive-info + contextual-grounding + prompt-attack + automated reasoning), Custom Models (fine-tune + continued pre-training + distillation + import), Bedrock Studio.
Knowledge Bases, Prompt Management & Flows
Amazon Bedrock Knowledge Bases managed RAG with S3 / Confluence / SharePoint / Salesforce / web crawler sources, default + fixed + semantic + hierarchical chunking, supported vector stores (OpenSearch Serverless default + managed, Aurora pgvector, Pinecone, Redis Enterprise, MongoDB Atlas, Neptune Analytics), RetrieveAndGenerate vs Retrieve, citations + filters + Bedrock rerank, Bedrock Data Automation for complex docs. Bedrock Prompt Management (versioning + approval workflows + CloudTrail). Bedrock Prompt Flows (visual DAG of prompt, Lambda, KB, condition, iterator, agent nodes).
Amazon Bedrock Agents & AgentCore
Bedrock Agents managed single-agent runtime with action groups + KBs + Guardrails. Bedrock AgentCore framework-agnostic production runtime: Runtime (sandbox), Gateway (MCP + auth), Memory (short + long-term), Identity (OAuth workforce + customer), Observability, Code Interpreter, Browser tool. Strands Agents AWS-maintained open-source SDK. Agent Squad multi-agent orchestrator. Amazon Augmented AI (A2I) for human-in-the-loop review of low-confidence outputs.
Vector Stores & Retrieval
Store selection (OpenSearch Serverless vector engine default, Aurora pgvector for transactional metadata, Neptune Analytics for GraphRAG, DocumentDB for MongoDB-compat, MemoryDB / ElastiCache for ultra-low-latency, DynamoDB for metadata references). Chunking strategies, embedding model selection (Titan Text Embeddings v2 at 256/512/1024 dims, Cohere Embed), hybrid search (BM25 + semantic), reranking, query transformation (expansion + decomposition + HyDE), incremental ingestion + scheduled refresh.
Amazon SageMaker AI Suite
Full ML platform: SageMaker AI (notebooks, training, hosting — real-time / serverless / async / batch transform / multi-model / shadow; MLOps Pipelines), SageMaker Unified Studio (Studio + Data + Lake Formation + Athena + Redshift + Bedrock in one pane), JumpStart (curated open-source + partner FM catalog for deploy or fine-tune), Data Wrangler, Ground Truth (labeling + RLHF), Clarify (bias + FM eval), Model Monitor (data / quality / bias / feature drift), Model Registry (approval gates), Processing (managed batch containers), Neo (edge compilation).
AWS AI Services & Amazon Q
Amazon Comprehend (NLP + PII), Kendra (enterprise semantic search + Intelligent Ranking), Lex (conversational bots), Rekognition (image + video), Textract (documents + forms + tables), Transcribe (ASR + Call Analytics + medical), Titan embeddings + image generator, Augmented AI (A2I). Amazon Q Business (enterprise assistant + Identity Center + 40+ connectors + response customisation), Q Business Apps (no-code mini-apps), Q Developer (coding assistant + /doc /test /transform agents for Java upgrades / .NET → Linux / mainframe), Amazon Connect with Contact Lens generative summaries.
Compute, Storage & Data
Compute: Lambda + Lambda@Edge, App Runner, EC2 with GPU (p5/p4d) + Trainium (trn2/trn1) + Inferentia (inf2/inf1) + general (g5/g6) + Capacity Blocks for ML, ECS + Fargate, EKS + Karpenter, ECR, Outposts + Wavelength. Storage: S3 (Intelligent-Tiering + Lifecycle policies + Cross-Region Replication), EBS gp3 / io2 Block Express, EFS, DataSync, Transfer Family. Data pipelines: Glue + Data Quality, EMR / EMR Serverless, Kinesis, MSK, Athena, QuickSight. Databases: Aurora pgvector, RDS, DynamoDB + Streams, DocumentDB vector search, ElastiCache / MemoryDB semantic cache, Neptune Analytics GraphRAG, OpenSearch Service.
Application Integration & APIs
EventBridge (bus + Pipes + Scheduler), Step Functions (Standard + Express, Map, task token, ReAct / circuit-breaker patterns), SNS + SQS, AppFlow (SaaS → AWS connectors), AppConfig (runtime feature flags + validators + CloudWatch alarm rollback for swapping prompts / models / Guardrails), Chatbot (Slack / Teams / Chime). API Gateway (REST + HTTP + WebSocket + authorizers + mTLS), AppSync (GraphQL + subscriptions for streaming tokens), CloudFront + Global Accelerator + Route 53 + ELB + PrivateLink, Amplify for front-end hosting + auth.
Security & Responsible AI
IAM + IAM Access Analyzer + IAM Identity Center + Cognito; KMS + AWS Encryption SDK for client-side envelope encryption; Secrets Manager for API keys; Macie for PII in S3 before ingest; AWS WAF rate-based rules on chat endpoints. Bedrock Guardrails for denied topics + PII redaction + prompt-injection + contextual grounding + relevance. Practical responsible-AI checklist covering fairness, explainability, privacy, safety, accountability, transparency, veracity, governance — mapped to AWS services and Bedrock + SageMaker Clarify features.
Observability, DevOps & Cost
CloudWatch (Bedrock InputTokens / OutputTokens / InvocationLatency / InvocationClientErrors + custom quality metrics), CloudWatch Logs + Bedrock Model Invocation Logging, CloudWatch Synthetics for prompt regression canaries, X-Ray distributed tracing, CloudTrail + Managed Grafana, Systems Manager + Service Catalog + Auto Scaling, Well-Architected Tool Generative AI lens. DevOps: CDK + CloudFormation + CodePipeline + CodeBuild + CodeDeploy + CodeArtifact + Amplify + CLI + SDKs. Cost: Cost Anomaly Detection + Cost Explorer; token minimisation (summarise, cap max_tokens, compress context); caching (ElastiCache semantic cache + Bedrock prompt caching); Batch Inference; Provisioned Throughput; Cross-Region Inference for capacity resilience.
Testing, Evaluation & Troubleshooting
Evaluation types: Bedrock Model Evaluation (automatic benchmarks + human workforce), SageMaker Clarify FM evaluation, RAG-specific metrics (RAGAS-style context precision + recall + answer relevance + faithfulness), generation metrics (BLEU / ROUGE / METEOR / BERTScore / perplexity). Troubleshooting: hallucinations (RAG + reranking + contextual-grounding + lower temperature), prompt injection (Guardrails + WAF + rate-limit), latency (smaller model + latency-optimized + parallelise + cache + async), throttling (Cross-Region Inference + Provisioned Throughput), agent runaway cost (Step Functions max-iteration + AppConfig kill-switch + Cost Anomaly Detection), retrieval drift (scheduled RAGAS eval + re-embed + re-chunk), quality regression after model swap (A/B via AppConfig + rollback).
Why This Cheat Sheet Helps
AIP-C01 is the deepest generative-AI developer exam AWS publishes. Questions reliably test the subtle differences you only notice after building with the platform: Bedrock Agents vs AgentCore, Knowledge Bases vs Kendra, Prompt Flows vs Step Functions, Provisioned Throughput vs Cross-Region Inference, which Guardrail filter covers which attack surface, when to fine-tune vs RAG, what BERTScore tells you that ROUGE does not, how to engineer a circuit breaker around a ReAct agent. This cheat sheet puts those decisions side by side with the exact AWS vocabulary examiners use.
It assumes you already understand foundation models + prompting + vectors. Use it in the final weeks to map the exam's surface area, reinforce the Bedrock ecosystem (KB + Agents + AgentCore + Guardrails + Prompt Management + Prompt Flows), and rehearse the responsible-AI controls and operational runbooks AWS expects in production GenAI systems.
How to Use It
Skim the whole sheet once to see how the five domains map to sections. Then hammer practice exams — for each wrong answer, find the relevant section and study the tables and decision trees. Pay extra attention to sections 2–4 (Bedrock + KB + Agents), 5 (Vector stores + retrieval), 13 (Security + Responsible AI), 16 (Testing + Troubleshooting), 17 (Reference Architectures), 18 (Scenario → Answer Patterns), 19 (Pitfalls), and 20 (Prompt Engineering deep dive).
In the final week, walk through the five domain weights against your confidence: FM Integration & Data (31%) → sections 1–5, 9, 10; Implementation & Integration (26%) → sections 4, 6, 8, 11, 12, 15; AI Safety, Security & Governance (20%) → sections 13, 21; Operational Efficiency (12%) → sections 14, 22, 23; Testing, Validation & Troubleshooting (11%) → sections 16, 24. Pair with CloudNinja's free AIP-C01 practice exam to surface gaps.
Frequently Asked Questions
Is this AWS Generative AI Developer Professional cheat sheet free?
Yes, completely free with no signup required. Download the PDF directly from CloudNinja and use it as a study reference for the AIP-C01 exam.
How much AWS experience do I need before AIP-C01?
AWS recommends two or more years of hands-on AWS development plus prior AI/ML experience. The exam is Bedrock-heavy and assumes fluent use of Knowledge Bases, Agents, AgentCore, Guardrails, Prompt Management, and Prompt Flows in production, plus SageMaker AI for fine-tuning and hosting. If you do not already hold the AI Practitioner (AIF-C01) and have built at least one RAG or agentic application, start there first.
How is AIP-C01 different from the AI Practitioner (AIF-C01)?
AIF-C01 is foundational — it tests vocabulary, concepts, and which service does what. AIP-C01 is professional-tier and tests how to build it. Expect longer scenarios with detailed implementation choices: which chunking strategy for this content type, when to fine-tune vs RAG, Bedrock Agents vs AgentCore, which vector store fits the transactional constraints, how to design circuit breakers around ReAct agents, which Guardrail + Macie + WAF combination covers a given threat model. Strong programming background expected.
Is this cheat sheet updated for the current AIP-C01 exam?
Yes, it is built directly from the current AIP-C01 exam guide (ai-professional-01) and audited against the full in-scope services list. It reflects current Bedrock features — AgentCore (Runtime / Gateway / Memory / Identity / Observability), Strands Agents, Agent Squad, Model Context Protocol, Cross-Region Inference, Latency-Optimized Inference, Bedrock Data Automation, Guardrails automated reasoning + contextual grounding, Bedrock Prompt Management + Prompt Flows, Amazon Nova model family, SageMaker Unified Studio, and AWS Well-Architected Generative AI Lens.