Unofficial study guide · Amazon Web Services

AWS Certified Generative AI Developer - Professional

An unofficial production GenAI engineering plan aligned to the current AIP-C01 domains and tasks.

Exam code AIP-C01 · Scope AIP-C01 · Reviewed

How to use this guide

The official target candidate has two or more years building production applications, general AI/ML and data-engineering experience, and about one year of hands-on generative AI implementation.

Study complete systems: requirements, model choice, data and retrieval, prompt governance, agents and tools, safety, privacy, deployment, observability, cost, evaluation, and troubleshooting.

Official domain map

D1 · 31%

Foundation Model Integration, Data Management, and Prompt Engineering

  • Requirements and architecture
  • Select and configure foundation models
  • Data pipelines
  • Vector stores and retrieval
  • Prompt engineering and governance
D2 · 26%

Implementation and Integration

  • Agents and tools
  • Deployment
  • Enterprise integration
  • APIs
  • Application integration
D3 · 20%

AI Safety, Security, and Governance

  • Input and output safety
  • Data privacy and security
  • Governance and compliance
  • Responsible AI
D4 · 12%

Operational Efficiency and Optimization

  • Cost and resource efficiency
  • Performance
  • Monitoring
D5 · 11%

Testing, Validation, and Troubleshooting

  • Evaluation
  • Troubleshooting

The largest domain joins model, data, retrieval, and prompts because application behavior emerges from their interaction; do not study prompt syntax in isolation.

Safety and evaluation must be lifecycle controls with owners, thresholds, datasets, release gates, and monitoring—not a final moderation API call.

Device-local diagnostic

Mark domains that need review

These selections stay in this browser. They are not an exam score and are never sent to Baitaphish.

No domains currently marked.

Diagnostic

Design one production GenAI feature and defend model, retrieval, permissions, evaluation, safety, deployment, observability, latency, and cost choices with measurable acceptance criteria.

  • Model and prompt fit
  • Retrieval and data
  • Agent/tool boundaries
  • Safety and governance
  • Operations and cost
  • Evaluation and troubleshooting

Shared foundations

These subjects are maintained once across the certification library; this guide applies them through its own domain lens.

Secure architecture

Reason about trust boundaries, resilience, data flows, network controls, and security tradeoffs before selecting products.

Data protection and cryptography

Choose controls for classification, lifecycle, encryption, keys, secrets, privacy, retention, and defensible deletion.

Identity and access

Explain authentication, authorization, federation, lifecycle controls, and least privilege across organizational and cloud boundaries.

Delivery and assurance

Build testing, software lifecycle, deployment, evaluation, audit, and evidence practices into normal delivery work.

Operations and incident response

Connect telemetry, triage, containment, recovery, change, and continuous improvement to measurable outcomes.

Risk and governance

Translate business context, policy, legal duties, control ownership, and evidence into defensible risk decisions.

Study sequence and reusable assets

  1. Model, data, retrieval, and prompts

    Build traceable inputs, retrieval, prompt versions, and model-selection evidence.

    • Retrieval application design: Separate retrieval, authorization, context construction, generation, and evaluation.
  2. Agents and integration

    Constrain tools, identities, APIs, state, errors, and enterprise boundaries.

    • Agent and tool boundary cases: Choose identities, permissions, confirmations, and failure handling.
  3. Safety and governance

    Apply privacy, content safety, responsible AI, approvals, and audit evidence through the lifecycle.

    • Safety, security, and governance cases: Turn risks into lifecycle controls and review evidence.
  4. Operations and evaluation

    Measure quality, safety, latency, cost, drift, and failure causes in production.

    • Production evaluation plan: Connect datasets, metrics, thresholds, releases, monitoring, and troubleshooting.

Common misconceptions

A larger model is the safest default.

Select against quality, latency, cost, context, modality, regional, safety, and governance requirements using representative evaluation.

RAG makes an answer grounded.

Retrieval can still return irrelevant, stale, unauthorized, or manipulated context; measure retrieval and generation separately and enforce access before retrieval.

A successful demo is evidence of production readiness.

Production readiness requires representative evaluation, threat controls, failure handling, observability, capacity, cost bounds, rollback, and accountable release criteria.

Seven-day experienced review sprint

Experienced application engineer with production GenAI exposure and seven focused synthesis days.

  1. Day 1 — Diagnostic; requirements, model selection, inference controls, and prompt governance.
  2. Day 2 — Data pipelines, embeddings, vector search, retrieval quality, freshness, and authorization.
  3. Day 3 — Agents, tools, identity, state, APIs, orchestration, and enterprise integration.
  4. Day 4 — Input/output safety, privacy, secrets, tenant isolation, governance, and responsible AI.
  5. Day 5 — Deployment, scaling, latency, caching, throughput, observability, and cost controls.
  6. Day 6 — Evaluation sets, metrics, human review, experiments, incident cases, and troubleshooting.
  7. Day 7 — Timed system-design scenarios; close only repeated evidence and lifecycle gaps.

Longer study path

Developer building production GenAI breadth over eight to twelve weeks.

  1. Baseline the official tasks and select one representative application as a running case study.
  2. Build a minimal model integration, then add versioned prompts, retrieval, access controls, and evaluation datasets.
  3. Add a constrained agent/tool workflow with least privilege, confirmations, timeout, idempotency, and audit evidence.
  4. Threat model safety, privacy, prompt injection, data poisoning, supply chain, tenant isolation, and model/provider failure.
  5. Operationalize quality, safety, latency, cost, drift, rollout, rollback, and incident response; then practice mixed scenarios.

Exam logistics

  • Confirm current availability, registration, delivery, timing, language, identification, and scoring details directly with AWS Certification.
  • Use the official guide's in-scope services and task statements as the boundary; fast-moving product announcements do not automatically change scored scope.
  • This unofficial guide is not affiliated with or endorsed by AWS and contains no recalled exam material.

Official sources