AIF-C01 Exam Guide: What the AWS Certified AI Practitioner Tests and How to Prepare
The AWS Certified AI Practitioner (AIF-C01) validates foundational knowledge of AI, machine learning, generative AI, AWS AI tools, business use cases, and responsible implementation. It serves candidates who use or evaluate AI/ML on AWS but do not necessarily build models or pipelines. This guide helps you decide whether your current AWS and AI exposure is sufficient, which domains deserve the most study time, how to practise the question formats, and when you are ready to schedule the exam.
What does AIF-C01 validate?
AIF-C01 tests whether you can explain AI, ML, and generative-AI concepts, select suitable technologies for business problems, and use those technologies responsibly. The emphasis is practical and foundational: choosing an approach, understanding tradeoffs, and recognising the AWS services involved rather than coding algorithms or implementing production infrastructure.
AWS describes the certification as focused on practical business applications of AI and foundational understanding of AI concepts and AWS AI tools. The exam objectives ask you to identify appropriate AI/ML and GenAI technologies for particular use cases, determine when a technology is suitable, and apply responsible-AI considerations.
A useful way to interpret the exam is as a decision-making assessment. A scenario may give you a business goal, data type, risk, or operating constraint and ask which approach best fits. Your answer should connect the requirement to a concept or service, while avoiding solutions that are unnecessarily complex, costly, opaque, or risky.
Who is the intended candidate?
AIF-C01 is aimed at people with up to 6 months of exposure to AI/ML technologies on AWS who use, but do not necessarily build, AI/ML solutions. It can suit business analysts, product and project professionals, technical sales staff, developers, cloud practitioners, and others who need a working vocabulary for AI decisions.
AWS recommends familiarity with core services and use cases including Amazon EC2, Amazon S3, AWS Lambda, Amazon Bedrock, and Amazon SageMaker AI. It also recommends knowledge of the AWS shared responsibility model, IAM, and AWS service pricing models. These are preparation expectations, not a stated requirement to hold another certification or to have a particular job title.
The target profile matters when you choose study material. You need enough technical understanding to distinguish a managed service from a model, a foundation model from a traditional ML model, and a security control from a governance process. You do not need to prepare as though AIF-C01 were a model-development or MLOps engineering exam.
What the exam does not expect
AWS lists developing or coding AI/ML models or algorithms, data or feature engineering, hyperparameter tuning, model optimisation, building and deploying AI/ML pipelines, mathematical or statistical analysis of models, and implementing security, compliance, or governance frameworks as out of scope. Do not let advanced implementation topics displace the published objectives.
This does not mean you can ignore how a model moves through its lifecycle. You should understand concepts such as training, inference, evaluation, deployment, monitoring, and retraining at a foundational level. The boundary is between explaining and choosing these concepts and carrying out the engineering work yourself.
How is the exam structured?
AWS lists AIF-C01 as a 90-minute exam with 65 questions. The exam includes 50 questions that affect your score and 15 unscored questions that AWS uses to evaluate content for possible future use. Your result is reported as a scaled score from 100–1,000, and the minimum passing score is 700.
The exam may include multiple-choice, multiple-response, ordering, and matching questions. Multiple-choice questions have one correct response and three distractors. Multiple-response questions require all correct responses to be selected. Ordering questions require a sequence, while matching questions require every pair to be matched correctly for credit.
Unanswered questions are scored as incorrect, and AWS states that there is no penalty for guessing. That makes question management part of your preparation: eliminate clearly unsuitable options, choose the best remaining response, and do not leave an item unanswered when you reach the end of your review.
The exam can be taken at a Pearson VUE testing centre or as an online-proctored exam. AWS lists Arabic, English, French, German, Italian, Japanese, Korean, Portuguese (Brazil), Spanish (Latin America and Spain), Simplified Chinese, and Traditional Chinese as offered exam languages. Confirm current appointment and delivery information through the official certification page before scheduling.
How should you read the score information?
Treat the passing score as an official scoring standard, not as a target percentage for practice tests. AWS reports a scaled score rather than presenting the result as a simple percentage, and section-level feedback should be interpreted cautiously. Use domain feedback to identify study priorities, not to infer an exact number of questions you must answer correctly in each domain.
Which domains deserve the most study time?
Study time should follow both the domain weighting and your personal weakness. Content Domain 3: Applications of Foundation Models represents 28% of scored content, Content Domain 2: Fundamentals of GenAI represents 24% of scored content, Content Domain 1: Fundamentals of AI and ML represents 20% of scored content, Content Domain 4: Guidelines for Responsible AI represents 14% of scored content, and Content Domain 5: Security, Compliance, and Governance for AI Solutions represents 14% of scored content.
The weighting is a planning signal, not permission to skip smaller domains. Domains 4 and 5 can expose gaps that are easy to overlook when a candidate focuses only on prompts and foundation models. Build a study plan that gives the largest blocks to Domains 3 and 2, then checks whether your understanding of basic ML, responsibility, security, compliance, and governance is strong enough to support scenario questions.
Domain 1: Fundamentals of AI and ML
Content Domain 1: Fundamentals of AI and ML represents 20% of scored content and covers terminology, practical use cases, and the AI/ML development lifecycle. You should be able to distinguish AI, ML, deep learning, neural networks, GenAI, LLMs, and agentic AI, then relate those concepts to an appropriate business problem.
Revise supervised, unsupervised, and reinforcement learning; labelled and unlabelled data; structured and unstructured data; and batch, real-time, asynchronous, and serverless inference. The domain also includes regression, classification, and clustering, plus applications such as computer vision, NLP, speech recognition, recommendation systems, fraud detection, forecasting, knowledge bases, and agentic AI.
A particularly important judgement is when AI/ML is not appropriate. AWS gives cost-benefit analysis and cases requiring a specific outcome rather than a prediction as examples. If a deterministic rule can meet the requirement more simply and reliably, the best answer may not involve ML.
Connect model metrics to the problem. Accuracy, precision, recall, and F1 score describe model performance, while cost per user, development costs, customer feedback, and ROI help assess business value. Also review the lifecycle from problem definition and data through training, inference, evaluation, deployment, monitoring, and retraining.
Domain 2: Fundamentals of GenAI
Content Domain 2: Fundamentals of GenAI represents 24% of scored content and covers GenAI concepts, capabilities and limitations, and AWS infrastructure for GenAI applications. This domain links vocabulary to business decisions: what a model can generate, where it can fail, how it is hosted, and which tradeoffs affect cost, latency, security, and delivery.
Know the roles of tokens, chunking, embeddings, vectors, transformer-based LLMs, FMs, multimodal models, and diffusion models. Be able to associate GenAI with summarisation, translation, code generation, image, video, or audio generation, assistants, customer-service agents, search, and recommendation engines without assuming every use case requires the same model type.
Revise the FM lifecycle: data selection, model selection, pre-training, fine-tuning, evaluation, deployment, and feedback. Token-based pricing affects inference cost and performance, so examine how input and output length, responsiveness, provisioned throughput, availability, redundancy, regional coverage, and custom models change a design decision.
Amazon Bedrock, Amazon SageMaker AI, SageMaker JumpStart, Amazon Quick, Kiro, Strands Agents, and Amazon Bedrock AgentCore appear among the AWS services and features identified for GenAI applications. Learn the role each service or feature plays at a conceptual level, and relate the choice to accessibility, speed to market, efficiency, security, compliance, and cost.
Domain 3: Applications of Foundation Models
Content Domain 3: Applications of Foundation Models represents 28% of scored content, the largest domain. It covers FM selection and application design, prompt engineering, training and fine-tuning, and performance evaluation. Allocate serious preparation time here, but study the topics as connected design choices rather than as an isolated vocabulary list.
For model selection, consider cost, modality, latency, multilingual capability, model size and complexity, customisation, input and output length, and prompt caching. In a scenario, start with the requirement rather than the service name. A low-latency interaction, a multilingual workflow, a regulated workload, and a long-document task may lead to different model choices.
RAG retrieves relevant information and supplies it to a foundation model so the response can be grounded in a knowledge source. Review Amazon Bedrock Knowledge Bases and the role of vector storage, including options such as Amazon OpenSearch Service, Amazon Aurora, Amazon Neptune, and Amazon RDS for PostgreSQL.
Compare in-context learning, RAG, fine-tuning, model distillation, and pre-training by asking what problem each approach solves and what it costs to operate. Fine-tuning requires suitable data preparation, including curation, governance, labelling, size, representativeness, and potentially human feedback. Pre-training is not a default answer merely because it offers maximum customisation.
Prompt engineering includes context, instruction, and negative prompts, along with zero-shot, single-shot, few-shot, chain-of-thought, and prompt-template techniques. Practise selecting a technique based on the desired response, available examples, clarity of instructions, and risk. Also know the risks of exposure, poisoning, hijacking, and jailbreaking, as well as prompt versioning and management with Amazon Bedrock Prompt Management.
FM evaluation should combine technical and business evidence. Review human-in-the-loop evaluation, benchmark datasets, Amazon Bedrock Model Evaluation, ROUGE, BLEU, BERTScore, and LLM-as-a-judge. For an application, examine task completion rate, user satisfaction, cost per interaction, productivity, engagement, conversion rate, average revenue per user, accuracy, or customer lifetime value when those measures align with the stated objective.
Domain 4: Guidelines for Responsible AI
Content Domain 4: Guidelines for Responsible AI represents 14% of scored content and tests responsible-system development plus transparency and explainability. Prepare to identify the risk in a scenario, the responsible practice that addresses it, and the tradeoff that may remain after a control is applied.
Review bias, fairness, inclusivity, robustness, safety, and veracity. Dataset characteristics such as diversity, representativeness, curation, and balance affect outcomes. Bias and variance can produce demographic impact, inaccuracy, overfitting, or underfitting, so connect each issue to an appropriate detection or monitoring activity such as label-quality analysis, human audits, or subgroup analysis.
AWS also identifies legal and business risks including intellectual-property infringement claims, biased outputs, loss of customer trust, end-user risk, and hallucinations. Amazon Bedrock Guardrails is an example of a tool for responsible-AI features. Learn its conceptual purpose, but do not treat a guardrail as a substitute for sound data selection, evaluation, human review, or access control.
Transparent and explainable models are not identical concepts. Ask whether users can understand how a decision was produced and whether the organisation can communicate the model’s behaviour, limits, data origins, and evaluation evidence. Review Amazon SageMaker Model Cards, Amazon Bedrock Model Evaluations, licensing, and open-source model considerations. Human-centred design includes user feedback and transparency about AI decisions.
Domain 5: Security, Compliance, and Governance
Content Domain 5: Security, Compliance, and Governance for AI Solutions represents 14% of scored content. It covers securing AI systems and recognising governance and compliance requirements. The strongest preparation connects a threat or obligation with the control, service, evidence, or process that addresses it.
Revise IAM roles, policies, and permissions; encryption at rest and in transit; data access control; privacy-enhancing technologies; data integrity; and the AWS shared responsibility model. The domain also names Amazon Macie, AWS PrivateLink, Amazon Bedrock AgentCore Identity, Policy in AgentCore, and Amazon Bedrock Guardrails as relevant security features or services.
For GenAI-specific threats, understand prompt injection, data leakage, output toxicity, insecure applications, vulnerability exposure, and inadequate audit trails. Security design may include output filtering and validation, logging AI interactions, threat detection, and vulnerability management. Hallucination detection and grounding can involve RAG, output validation, and confidence scoring.
Governance is broader than a firewall or IAM policy. Review data lifecycles, residency, retention, logging, monitoring, and observation, together with policy review cadence, transparency standards, team training, and governance frameworks such as the Generative AI Security Scoping Matrix. AWS identifies AWS Config, Amazon Inspector, AWS Artifact, AWS CloudTrail, and AWS Trusted Advisor as services that can assist governance or regulatory compliance.
Which AWS services should you revise?
Use the official in-scope list as a boundary for service revision, not as a promise that every listed service will receive equal attention. The list is non-exhaustive and subject to change, so check it again near your exam appointment. Learn why a service belongs in a scenario and what category of problem it addresses.
The list spans analytics, cloud financial management, compute, containers, databases, developer tools, machine learning, management and governance, networking and content delivery, security, identity and compliance, and storage. It includes services such as Amazon S3, Amazon EC2, AWS Lambda, IAM, AWS KMS, Amazon CloudWatch, AWS CloudTrail, Amazon Bedrock, Amazon SageMaker AI, Amazon OpenSearch Service, Amazon DynamoDB, Amazon VPC, Amazon Macie, and AWS Config.
A practical revision method is to build a service-to-purpose table. For each service, record its category, the AI or cloud decision it supports, one security or cost consideration, and one service it might be confused with. For example, distinguish a service that provides foundation-model access from a service used to develop, deploy, monitor, or store data for an AI application. Avoid memorising the catalogue without understanding those relationships.
How should you prepare without overstudying?
Start with the official exam guide and domain pages, then turn each task statement into a question you can answer without notes. Use the domain weighting to allocate time, but use self-testing to reallocate it. Reading service descriptions repeatedly is less useful than explaining a design choice and defending why competing options are less suitable.
Create five study folders or note sections, one for each domain. For every objective, write three items: a plain-language definition, a business scenario, and the deciding factor that separates the best answer from a tempting alternative. This forces you to learn relationships such as model choice versus customisation method, responsible-AI risk versus security threat, and model metric versus business metric.
Use a small comparison grid for recurring distinctions. Examples include classification versus regression, supervised versus unsupervised learning, traditional ML versus an FM, RAG versus fine-tuning, prompt engineering versus model training, transparency versus explainability, and security controls versus governance processes. The grid should contain the purpose, typical input or output, primary advantage, limitation, and a scenario where the choice is inappropriate.
Practise explaining answers aloud or in writing. If you can name a service but cannot state why it fits the requirement, your knowledge is probably recognition-based rather than decision-ready. Conversely, do not spend disproportionate time implementing code or tuning a model: AWS explicitly places those tasks outside the target candidate’s expected scope.
A four-pass study sequence
Pass one establishes vocabulary. Read Domains 1 and 2 and define the core AI, ML, GenAI, FM, inference, data, lifecycle, and AWS terms. Do not move on while terms such as embeddings, vectors, tokens, RAG, fine-tuning, and inference remain interchangeable in your notes.
Pass two builds design judgement. Focus on Domain 3 and compare model selection criteria, inference parameters, prompt techniques, RAG, vector stores, customisation approaches, data preparation, and evaluation methods. For each topic, write a short scenario where the option is useful and another where it creates an unnecessary tradeoff.
Pass three covers risk and control. Study Domains 4 and 5 together only where that clarifies a distinction; keep their objectives separate in your notes. Responsible AI asks whether the system is fair, safe, truthful, inclusive, robust, transparent, and explainable. Security and governance ask how data, identities, infrastructure, interactions, evidence, and organisational processes are protected and controlled.
Pass four is retrieval practice. Work through mixed questions, including multiple-response, ordering, and matching tasks. Review every incorrect answer and every guess. Record the clue you missed, the rule that resolves it, and the distractor logic. Then retest the same concept in a different scenario rather than memorising the wording of one question.
How to use hands-on practice
Hands-on work is useful when it makes an abstract distinction concrete, but it should remain proportional to a foundational exam. A short exercise can help you understand how a prompt changes with context, how retrieved information supports an answer, how permissions affect access, or how a metric relates to a business objective.
Keep a decision log for each exercise: the requirement, chosen service or technique, alternative considered, cost or latency implication, security or responsibility concern, and evidence you would monitor. This mirrors the exam’s emphasis on selecting an appropriate technology rather than proving that you can build a complete application.
Do not use live exam content, leaked questions, or memorisation-based dumps as a preparation strategy. They do not establish understanding, may be inaccurate, and cannot substitute for learning the published objectives. Use legitimate practice questions only to diagnose reasoning gaps, then return to the official domain objective that exposes the gap.
What should a practical roadmap look like?
A flexible roadmap works better than a rigid calendar because candidates begin with different AWS and AI experience. Use the stages below in order, and shorten or repeat a stage based on evidence from self-tests. The finish line is not completing a video course; it is making consistent, source-grounded choices in unfamiliar scenarios.
Stage one is a baseline and scope check. Read the target candidate description, recommended AWS knowledge, out-of-scope tasks, question types, and domain weightings. Mark each objective as confident, partly understood, or new. Schedule the exam only after checking the current official delivery, language, and appointment information.
Stage two is foundational vocabulary and use-case mapping. Cover Domain 1 first, then Domain 2. Build a one-page lifecycle diagram and a use-case map linking business needs to techniques such as regression, classification, clustering, traditional ML, FMs, or GenAI. Add a “not appropriate” column so you practise recognising when a simpler or deterministic solution is preferable.
Stage three is FM application design. Spend the largest single block on Domain 3. Compare model selection, prompt construction, inference parameters, RAG, vector storage, fine-tuning, distillation, pre-training, evaluation, and business metrics. After each topic, answer a scenario without looking at your notes and explain why two distractors fail.
Stage four is responsible operation. Study Domains 4 and 5 with short scenario cards. Each card should state a risk such as bias, hallucination, prompt injection, data leakage, poor lineage, unauthorised access, or unclear accountability. On the reverse, write the relevant practice, service, or governance activity and the limitation of that response.
Stage five is mixed review and exam rehearsal. Use timed sets that include every published question type. Practise reading the requirement before the options, identifying the constraint, eliminating mismatched services, and checking that a multiple-response answer includes every required selection. Review errors by objective rather than by question number.
Stage six is a final evidence check. Revisit the official guide, domain pages, and in-scope services list for changes. Confirm your appointment details and chosen delivery method through the official AWS certification route. Stop adding new peripheral topics when your remaining time is better spent correcting repeated errors in the blueprint.
A sample weekly rhythm
On the first study session of a week, learn one domain objective set and make concise notes. On the next session, apply those concepts to scenarios. Use a later session for retrieval without notes, followed by a targeted review of errors. Finish the week with a mixed set that includes older material, because spaced recall reveals whether a definition has become usable knowledge.
Keep an error register with four columns: objective, wrong assumption, evidence that resolves it, and the next review date. Common entries might include confusing a business metric with a model metric, choosing fine-tuning when RAG would provide current knowledge, treating a guardrail as complete security, or selecting AI when the requirement calls for a fixed outcome.
Which mistakes reduce preparation quality?
The most damaging mistake is studying the technology catalogue without the decision criteria. AIF-C01 asks you to identify appropriate technologies and responsible uses, so memorising names without understanding purpose, limitations, cost, security, and business fit produces fragile knowledge.
Another mistake is treating GenAI as the whole exam. Domain 3 is the largest domain, but Domains 1, 2, 4, and 5 together cover foundational AI/ML, GenAI fundamentals, responsibility, security, compliance, and governance. A candidate who ignores the smaller domains may miss straightforward scenario points and fail to recognise risks in otherwise attractive GenAI designs.
Do not confuse an AWS service’s existence with a requirement to use it. Start with the business objective, data, latency, explainability, compliance, access, and cost constraints. Then select the least complicated option that satisfies them. If the question asks for a model evaluation method, a storage option, a security control, or a governance process, answer that specific need rather than naming a broad platform.
Avoid passive completion. Finishing a course, highlighting a domain page, or copying definitions does not show that you can retrieve and apply the concept. Convert every note into a question and revisit it after a gap. Include questions you answered correctly by guessing, since a lucky choice is not dependable evidence.
Finally, do not infer more precision than AWS provides. Domain percentages describe scored content, while the exam includes scored and unscored questions and reports a scaled score. Use official facts for planning, but do not turn them into an invented pass-percentage formula or a guaranteed number of correct answers.
How can you tell whether you are ready?
You are closer to readiness when you can explain every domain objective in plain language, choose between competing approaches from a scenario’s constraints, identify the risk behind a responsible-AI or security option, and handle all listed question types without relying on familiar wording. Your review log should show fewer repeated conceptual errors, not merely faster completion.
Before scheduling, perform a blind blueprint check. Take each task statement in order and write the answer to “What decision could this objective require me to make?” If the answer is vague, return to that domain. Also verify that your AWS service knowledge includes the recommended core services and the current in-scope list rather than an outdated personal catalogue.
What should you do on exam day?
Use the delivery instructions for your selected Pearson VUE testing centre or online-proctored appointment as the authority for operational requirements. The study decision is simpler: arrive or connect prepared to read carefully, manage time across 65 questions, and leave no question unanswered.
Read the stem before studying the options. Identify whether it asks for the most appropriate service, technique, metric, control, or explanation. Look for constraints involving cost, latency, modality, data access, compliance, transparency, accuracy, or the need for a deterministic result. Those constraints often separate the correct response from a technically possible but unsuitable distractor.
For multiple-response questions, verify that each selected response addresses the stated requirement and that you have not selected an attractive extra. For ordering questions, identify the lifecycle or operational sequence before placing responses. For matching questions, eliminate pairs using distinctive purpose and scope, then check every remaining pair.
Flag uncertainty and continue rather than spending too long on one item. Return with the objective and constraint in mind. Because unanswered questions are scored as incorrect and AWS states there is no penalty for guessing, make a final pass to provide an answer to every question.
What should you do next?
Begin with the official AIF-C01 exam guide, record your baseline against every task statement, and create a study schedule weighted toward Domains 3 and 2 while protecting time for the other three domains. Then use the in-scope services page to check your AWS vocabulary and the official certification page to confirm current scheduling details.
A sensible first study session is to explain the difference between a traditional ML solution and a foundation-model application, then map each to a business use case and a measurable outcome. Follow that with the Domain 1 lifecycle and use-case objectives. This gives later work on prompts, RAG, evaluation, responsible AI, security, and governance a practical frame.
Recheck the official sources before booking because service lists, delivery information, languages, and other exam details can change. Keep your preparation anchored to the published objectives, use practice material to test reasoning rather than memorisation, and schedule only when your error register shows that you can apply the concepts consistently.
Conclusion
AIF-C01 preparation is most effective when it combines foundational vocabulary with disciplined technology selection. Learn the five domains, prioritise foundation-model applications and GenAI fundamentals, and then use responsible-AI, security, compliance, and governance scenarios to test whether your decisions are safe and defensible. The practical next step is to complete a blueprint-based baseline and turn every weak objective into a scenario you can solve without notes.