30 free AWS AI Practitioner (AIF-C01) practice questions
Thirty questions split the way the official exam guide weights the five domains, 6 on AI and ML fundamentals, 7 on generative AI, 9 on foundation model applications, 4 on responsible AI and 4 on security and governance. They follow version 1.1 of the exam guide, published by AWS on April 30, 2026, which added agentic AI, Kiro, Amazon Bedrock AgentCore and Strands Agents. Some ask for two answers, like the real exam.
The part that matters to me is the proof. After you check an answer, you get the sentence from the AWS documentation that backs it, with the link. If AWS changes a page and a question goes stale, you will see it before I do, and I would like to hear about it.
A warehouse wants cameras to spot damaged boxes on a conveyor belt and flag them automatically. Which field of AI does this use case belong to?
Answer B. The system must extract information from images or video of the boxes. Deriving meaning from visual inputs is the definition of computer vision.
- A. Natural language processing works with human language in text or speech, not images.
- C. Speech recognition converts spoken audio into text.
- D. Time-series forecasting predicts future values from ordered historical data, not from camera images.
“Computer vision is a field of artificial intelligence (AI) that enables computers to derive meaningful information from digital images, videos, and other visual inputs.”
aws.amazon.com/what-is/computer-vision/
A utility collects a reading from each smart meter every 15 minutes, each with a timestamp. It wants to use this history to study consumption patterns over the year. What type of data is this?
Answer D. Each value is tied to a point in time and the readings form an ordered sequence. Data recorded at regular intervals and analyzed in time order is time-series data, typical of IoT sensors.
- A. Meter readings are numeric values, not pictures.
- B. The readings are numbers with timestamps, not free text.
- C. Semi-structured data mixes unstructured content with tags, which does not describe regular numeric readings.
“A time series database (TSDB) is a type of database management system that is structured for storing and analyzing time-ordered data. TSDBs are capable of handling large amounts of continuous event stream data, such as Internet of Things (IoT) sensor data from a fleet of devices.”
aws.amazon.com/what-is/time-series-database/
A security team has months of network traffic records with no labels. It wants to discover natural groups of traffic types so analysts can spot suspicious ones. Which ML technique fits best?
Answer A. The data has no labels and the goal is to find groups of similar records. Clustering is the unsupervised technique that groups data inputs so they can be studied as a whole.
- B. Linear regression predicts a numeric value and needs a known target.
- C. Classification needs labeled examples of each class, which the team does not have.
- D. Reinforcement learning learns actions from rewards, not groups in existing records.
“The clustering unsupervised learning technique groups certain data inputs together, so they may be categorized as a whole. [...] An example of clustering is identifying different types of network traffic to predict potential security incidents.”
aws.amazon.com/compare/the-difference-between-machine-learning-supervised-and-unsupervised/
A marketing team wants one model that can draft campaign emails, summarize customer feedback and answer product questions, with little labeled data available. Which approach fits best?
Answer C. The tasks are varied and generative, and the team lacks labeled data. A pre-trained foundation model handles many general tasks from prompts, while traditional ML models usually do one specific task.
- A. Regression predicts numbers and cannot write emails or summaries.
- B. Clustering groups similar feedback but does not generate text or answer questions.
- D. Hand-written rules cannot cover open language tasks like drafting emails.
“The size and general-purpose nature of FMs make them different from traditional ML models, which typically perform specific tasks, like analyzing text for sentiment, classifying images, and forecasting trends.”
aws.amazon.com/what-is/foundation-models/
An architect puts a stable API in front of a model endpoint instead of letting applications call the model code directly. What is the main benefit?
Answer B. An API layer separates consuming applications from the model behind it. The team can update or replace the model while clients keep the same contract.
- A. An API does not remove the need to train the model.
- C. Evaluation is still needed before any release.
- D. An API changes access, not model accuracy.
“Expose ML endpoints through APIs so changes to the model can be introduced without disrupting upstream communications.”
docs.aws.amazon.com/wellarchitected/latest/machine-learning-lens/mlrel01-bp01.html
A model has run in production for six months. Which TWO kinds of drift can Amazon SageMaker Model Monitor detect so the team knows when to retrain? (Select TWO.)
Answer A, C. Model Monitor watches data quality and model quality, along with bias and feature attribution drift. Alerts on these deviations tell the team when to retrain the model.
- B. User counts are an account matter, not model drift.
- D. Billing is not monitored by Model Monitor.
- E. Code style has no link to model behavior in production.
“Data quality - Monitor drift in data quality. Model quality - Monitor drift in model quality metrics, such as accuracy.”
docs.aws.amazon.com/sagemaker/latest/dg/model-monitor.html
A team is building semantic search over product descriptions. Which TWO statements about embeddings and vector databases are correct? (Select TWO.)
Answer A, C. Embedding models turn data into vectors that carry meaning and context. A vector database stores these vectors and finds the nearest neighbors quickly, which is how similar items are retrieved.
- B. Vector databases store high-dimensional vectors, not just plain text for keyword match.
- D. Embeddings work for many data types, including images.
- E. The vectors come from an embedding model, so a model is still needed.
“Embeddings encode all types of data into vectors that capture the meaning and context of an asset. [...] They add additional capabilities for efficient and fast lookup of nearest-neighbors in the n-dimensional space.”
aws.amazon.com/what-is/vector-databases/
An AI agent must read records from a company ticketing system and also call another agent that handles billing. Which open protocol provides a communication layer for both kinds of connection?
Answer D. MCP is an open protocol that connects agents to external data, tools, and services. It can also carry communication between agents.
- A. SMTP sends email and is not designed for agent tool access.
- B. FTP transfers files and has no notion of agent tools.
- C. BGP routes traffic between networks on the internet.
“MCP provides a communication layer that enables agents to interact with external data and services and can also be used to enable agents to interact with other agents.”
docs.aws.amazon.com/prescriptive-guidance/latest/agentic-ai-frameworks/getting-started-with-mcp.html
A bank's chatbot confidently quotes a fee policy that does not exist anywhere in the bank's documents. The team wants to track how often this happens in production. Which metric fits?
Answer B. Generating confident but false information is called hallucination. Tracking the hallucination rate shows how often the model produces false or misleading content.
- A. Throughput measures request volume, not correctness.
- C. GPU utilization measures resource use, not false answers.
- D. Net promoter score measures customer satisfaction, not factual errors.
“Hallucination rates - frequency of generating false or misleading information”
docs.aws.amazon.com/prescriptive-guidance/latest/gen-ai-lifecycle-operational-excellence/prod-monitoring-performance.html
A subscription app adds AI-generated personalized content. Leadership wants a business value metric for its ROI dashboard, not a technical one. Which metric fits best?
Answer D. An ROI dashboard pairs cost metrics with business value metrics such as revenue lift, hours saved, and customer satisfaction. A rise in average revenue per user is a form of revenue lift.
- A. Token throughput is a technical performance metric.
- B. GPU utilization is an infrastructure metric.
- C. Parameter count describes the model, not business results.
“It should integrate financial metrics (such as cost per interaction and total infrastructure spend) with business value metrics (such as hours saved, revenue lift, and CSAT score improvements).”
docs.aws.amazon.com/prescriptive-guidance/latest/gen-ai-lifecycle-operational-excellence/prod-value.html
A company has built several agents with LangGraph and wants an AWS platform to deploy and operate them securely at scale, with any framework and any foundation model. Which service fits best?
Answer A. Amazon Bedrock AgentCore is an agentic platform for building, deploying, and operating agents. It works with open-source frameworks such as LangGraph, CrewAI, and Strands Agents and with models inside or outside Amazon Bedrock.
- B. JumpStart is a catalog of pretrained models, not a platform to run framework-based agents.
- C. Knowledge Bases provide retrieval for RAG, they do not host and operate agents.
- D. Quick Sight is a business intelligence feature of Amazon Quick.
“Amazon Bedrock AgentCore is an agentic platform for building, deploying, and operating highly effective agents securely at scale using any framework and foundation model.”
docs.aws.amazon.com/bedrock-agentcore/latest/devguide/what-is-bedrock-agentcore.html
A board asks why the company should build its generative AI applications on AWS. Which set of benefits does AWS state for generative AI on AWS?
Answer C. AWS presents generative AI on AWS as easy to build and scale. It highlights enterprise-grade security and privacy, a choice of leading foundation models, ready applications, and a data-first approach.
- A. Inference is billed and security is a shared responsibility.
- B. AWS offers models from many providers, and prices depend on usage.
- D. Customers do not own base model weights and keep their own responsibilities.
“With generative AI on AWS, you get enterprise-grade security and privacy, access to industry-leading FMs, generative AI-powered applications, and a data-first approach.”
aws.amazon.com/what-is/generative-ai/
A company uses Amazon Bedrock service tiers for different workloads. Which two statements about the tiers are correct? (Select TWO.)
Answer B, D. Flex suits jobs such as model evaluations or summarization that can wait, in exchange for a discount. Priority costs more than standard on-demand and gives the fastest responses for customer-facing workloads.
- A. Standard is the default tier and needs no reservation.
- C. Priority requests are served ahead of Standard and Flex requests.
- E. Priority needs no prior reservation, you set a request parameter.
“For workloads that can handle longer processing times, the Flex tier offers cost-effective processing for a pricing discount. [...] The Priority tier delivers the fastest response times for a price premium over standard on-demand pricing.”
docs.aws.amazon.com/bedrock/latest/userguide/service-tiers-inference.html
Users of a chatbot upload a long product manual and then ask many questions about it in the same session. The company wants to cut response latency and input token costs on Amazon Bedrock. Which feature fits best?
Answer B. Prompt caching lets the model reuse a long prefix that repeats across requests instead of processing it each time. A manual that is queried many times is the textbook case, and it lowers both latency and input token cost.
- A. Distillation creates a new model through training. It does not avoid reprocessing the same manual on every request.
- C. Temperature changes randomness. It has no effect on cost or latency of repeated context.
- D. Batch inference is asynchronous and does not suit an interactive chat session.
“Prompt caching can help when you have workloads with long and repeated contexts that are frequently reused for multiple queries.”
docs.aws.amazon.com/bedrock/latest/userguide/prompt-caching.html
A company wants its assistant to know about new internal reports every week. Retraining a foundation model each week is being discussed. Why is RAG usually the cheaper choice here?
Answer B. Retraining a model for each update requires large compute and money. RAG keeps the model as is and supplies fresh documents at inference time, which makes it the cost-effective way to add new data.
- A. RAG does not touch model weights. It supplies data in the prompt.
- C. The model still runs and is still billed for each request.
- D. RAG relies on a data source and usually a vector store, which has its own cost.
“The computational and financial costs of retraining FMs for organization or domain-specific information are high. RAG is a more cost-effective approach to introducing new data to the LLM.”
aws.amazon.com/what-is/retrieval-augmented-generation/
A user asks a model to classify a headline as positive, negative or neutral, and gives no example classifications in the prompt. Which prompting technique is this?
Answer A. Zero-shot prompting gives the task with no examples and relies on the model's general training. It suits simple tasks the model already handles well.
- B. Few-shot prompting includes several example input and output pairs.
- C. Single-shot prompting includes exactly one example pair.
- D. Chain-of-thought asks the model to reason step by step. The prompt here only states the task.
“example of a zero-shot sentiment classification prompt where no example input-output pair is provided in the prompt text”
docs.aws.amazon.com/bedrock/latest/userguide/prompt-engineering-guidelines.html
A developer adds an Amazon Bedrock guardrail with a prompt attack filter to an application that calls InvokeModel. The developer's own system prompt keeps getting flagged as an attack. What should the developer do so that only user input is checked for prompt attacks?
Answer A. A system prompt and a hijacking attempt can look alike. Input tags mark which part of the prompt came from the user, so the prompt attack filter evaluates that part and leaves the developer's system prompt alone.
- B. Setting the strength to None turns off attack detection for users too.
- C. A Knowledge Base supplies retrieved documents. It does not tell the guardrail which text is user input.
- D. Temperature changes output randomness. It has no effect on guardrail filtering.
“With input tags for guardrails, the prompt attack filter will detect malicious intents in user inputs, while ensuring that the developer provided system prompts remain unaffected.”
docs.aws.amazon.com/bedrock/latest/userguide/guardrails-prompt-attack.html
During pre-training, a foundation model learns from a huge corpus of text that nobody has labeled. How does the model get a learning signal from this data?
Answer B. Foundation models are pre-trained with self-supervised learning. The training objective, such as predicting the next or a masked word, builds its own labels from the raw text, so no manual labeling is needed at that scale.
- A. Labeling a corpus of that size by hand is not how pre-training works.
- C. Reward functions belong to reinforcement learning methods, not to standard pre-training.
- D. That describes distillation, which happens after a capable model already exists.
“Foundation models use self-supervised learning to create labels from input data.”
aws.amazon.com/what-is/foundation-models/
A team will use instruction-based fine-tuning on a pre-trained model. What form should its training examples take?
Answer A. Instruction tuning is supervised. Each example pairs an instruction style prompt with the expected response, so the model learns to follow similar requests.
- B. Raw documents with no outputs fit continued pre-training or domain adaptation.
- C. Scores alone, without prompts and responses, cannot teach the model a task.
- D. Stored embeddings support retrieval at query time, not instruction tuning.
“Instruction-based fine-tuning uses labeled examples to improve the performance of a pre-trained foundation model on a specific task. The labeled examples are formatted as prompt, response pairs and phrased as instructions.”
docs.aws.amazon.com/sagemaker/latest/dg/jumpstart-foundation-models-fine-tuning-instruction-based.html
A healthcare company is labeling examples to fine-tune a model. A manager wants to cut labeling time by accepting rough, unchecked labels. Why is this a risk?
Answer C. Labels are the ground truth the model learns from. Inaccurate labels teach the model wrong answers, so careful labeling is worth the time.
- A. The job still runs with poor labels, it just learns the wrong things.
- B. Label quality has no real effect on storage cost.
- D. Supervised fine-tuning depends directly on the labels.
“The accuracy of your trained model will depend on the accuracy of your ground truth, so spending the time and resources to ensure highly accurate data labeling is essential.”
aws.amazon.com/what-is/data-labeling/
A bank runs an LLM-as-a-judge evaluation in Amazon Bedrock. It wants to check whether answers respect the exact directions in the prompt and whether they suit a professional setting. Which two built-in metrics should it select? (Select TWO.)
Answer B, E. Following instructions checks how well a response respects the directions in the prompt. Professional style and tone checks whether style, formatting and tone fit a professional setting.
- A. Refusal detects when the model declines to answer.
- C. Stereotyping looks for stereotypes in the content.
- D. Context coverage is a RAG retrieval metric, not a judge metric for model answers.
“measures how well the model's response respects the exact directions found in the prompt. [...] measures how appropriate the response's style, formatting, and tone is for a professional setting.”
docs.aws.amazon.com/bedrock/latest/userguide/model-evaluation-metrics.html
A travel booking agent holds multi-turn conversations. The team wants to know whether each session achieved everything the user wanted. Which AgentCore built-in evaluator fits?
Answer D. Goal success rate is a session-level evaluator. It reviews the whole conversation to judge whether all user goals were met, which matches the team's question.
- A. Tool parameter accuracy checks individual tool calls, not the whole session outcome.
- B. Conciseness judges wording length, not whether goals were met.
- C. Stereotyping looks for biased content, not task success.
“The goal success rate evaluator assesses whether an AI assistant successfully completed all user goals within a conversation session.”
docs.aws.amazon.com/bedrock-agentcore/latest/devguide/prompt-templates-builtin.html
A RAG application answers employee questions from internal policy documents. Sometimes the model adds details that are not in the retrieved passages. Which Amazon Bedrock Guardrails feature helps detect and filter these answers?
Answer D. Contextual grounding checks flag responses that are not grounded in the source information or that do not answer the user's query. This is the guardrail built for hallucinations in RAG applications.
- A. Word filters only block listed words or phrases.
- B. Content filters detect harmful categories such as hate or insults, not unsupported facts.
- C. Denied topics block subjects you define, not answers that drift from the retrieved text.
“Contextual grounding checks - can help you detect and filter hallucinations in model responses if they are not grounded (factually inaccurate or add new information) in the source information or are irrelevant to the user's query.”
docs.aws.amazon.com/bedrock/latest/userguide/guardrails-components.html
A data scientist checks the class imbalance (CI) metric in SageMaker Clarify for a gender facet and gets a value very close to 0. What does this value indicate about the training data?
Answer A. A CI value near zero means the facets have close to equal numbers of samples, which is a balanced distribution. Values near 1 or minus 1 signal strong imbalance and a higher risk of biased predictions.
- B. A dataset with only one facet gives a CI of 1 or minus 1, not 0.
- C. CI counts samples per facet and says nothing about label accuracy.
- D. CI is a pre-training metric on the data and does not measure overfitting.
“Values of CI near zero indicate a more equal distribution of members between facets and a value of zero indicates a perfectly equal partition between facets and represents a balanced distribution of samples in the training data.”
docs.aws.amazon.com/sagemaker/latest/dg/clarify-bias-metric-class-imbalance.html
Which two benefits does AWS list for explanations of ML model predictions? (Select TWO.)
Answer A, D. AWS says explanations support auditing and regulatory requirements, build trust and support human decisions, and help debug and improve models. An explainable model can be checked and fixed in ways a black box cannot.
- B. Explanations describe a trained model and do not replace training data.
- C. Generating explanations adds work and does not lower inference cost.
- E. Explanations can help find bias but cannot guarantee it is absent.
“You can use explanations for auditing and meeting regulatory requirements, building trust in the model and supporting human decision-making, and debugging and improving model performance.”
docs.aws.amazon.com/sagemaker/latest/dg/clarify-model-explainability.html
A team uses feature importance scores to interpret a complex model before a business decision. Which two statements reflect AWS guidance on these scores? (Select TWO.)
Answer A, C. AWS warns that feature importance scores can be misleading and should be analyzed carefully. It recommends validation with subject matter experts, because misread scores can lead to poor business decisions.
- B. Interpretation methods rely on simplifying assumptions that can themselves introduce inaccuracy.
- D. Interpretability does not replace performance metrics such as accuracy.
- E. Feature importance methods such as SHAP are used on complex models too.
“Feature importance scores can be misleading and should be analyzed carefully, including validation with subject matter experts if possible.”
docs.aws.amazon.com/prescriptive-guidance/latest/ml-model-interpretability/overview.html
A team deploys an AI agent that must call a third-party calendar API on behalf of each signed-in user, while keeping audit trails of that access. Which capability is designed for this?
Answer B. AgentCore Identity manages authentication, authorization, and credentials for agents. It lets an agent reach AWS resources and third-party services on behalf of users with security controls and audit trails.
- A. Guardrails filter content in prompts and responses, they do not manage credentials.
- C. Macie discovers sensitive data in Amazon S3.
- D. AWS Artifact provides compliance documents, not agent credentials.
“It provides secure authentication, authorization, and credential management capabilities that enable agents and tools to access AWS resources and third-party services on behalf of users while helping to maintain strict security controls and audit trails.”
docs.aws.amazon.com/bedrock-agentcore/latest/devguide/identity.html
A data lake holds training data with a column of national ID numbers. Data scientists may read the table but must not see that column. Which service gives this fine-grained control?
Answer B. Lake Formation lets administrators define access policies down to the column, row, and cell level. The team can grant the table while hiding the sensitive column.
- A. GuardDuty detects threats, it does not grant or restrict column access.
- C. Trusted Advisor gives best practice recommendations, not data permissions.
- D. Inspector finds software vulnerabilities in workloads.
“You can define security policies that restrict access to data at the database, table, column, row, and cell levels.”
docs.aws.amazon.com/lake-formation/latest/dg/what-is-lake-formation.html
A regulator asks a healthcare startup for the AWS SOC reports that cover the infrastructure its AI system runs on. Where can the startup download these reports?
Answer C. AWS Artifact gives on-demand access to AWS security and compliance documents such as SOC, ISO, and PCI reports. Customers can hand these to auditors or regulators.
- A. Trusted Advisor gives recommendations for your account, not third-party audit reports.
- B. CloudTrail records API activity.
- D. Inspector produces vulnerability findings, not AWS audit reports.
“AWS Artifact provides on-demand downloads of AWS security and compliance documents.”
docs.aws.amazon.com/artifact/latest/ug/what-is-aws-artifact.html
A team wants AWS CloudTrail to record every InvokeAgent call made to its Amazon Bedrock agents. What must the team do?
Answer D. Bedrock logs agent runtime calls such as InvokeAgent as CloudTrail data events. Data events are not logged by default, so the team must add an advanced event selector for agent aliases.
- A. InvokeAgent is a data event, and CloudTrail does not log data events by default.
- B. Macie scans S3 data and does not change CloudTrail logging.
- C. Model invocation logging is a separate feature and does not create CloudTrail data events.
“To log InvokeAgent calls, configure advanced event selectors to record data events for the AWS::Bedrock::AgentAlias resource type.”
docs.aws.amazon.com/bedrock/latest/userguide/logging-using-cloudtrail.html
These 30 come from a set of 300, four full 65 question exams at the same weights plus a 40 question drill, in one PDF with the same sourced answer key. It is 12 euros on Ko-fi, no account needed to buy.
If you would rather sit them timed in the browser with a score by domain at the end, the same 300 questions are also a Udemy practice test course, 12.99 dollars with that link until November 4.
Preparing for Cloud Practitioner too? AIF-C01 and CLF-C02 together are 19 euros, one PDF of 600 questions.

