Practice Exams:

Latest Posts

Amazon AWS AIP-C01: Multi-Agent Workflows on AWS

Multi-agent workflows divide a complex task among specialized agents instead of asking one large agent to understand every domain, tool, and permission boundary. On AWS, the current architectural center for new agent development is Amazon Bedrock AgentCore. AWS moved Amazon Bedrock Agents into maintenance mode as “Bedrock Agents Classic” on July 30, 2026, and recommends AgentCore for new agent workloads and future migration. That platform shift matters for multi-agent design. Bedrock Agents Classic still supports supervisor and collaborator agents for existing customers, but AWS’s current maintenance-mode guidance says advanced multi-agent…

Read More

Amazon AWS AIP-C01: Latency Tuning for Bedrock Apps

Latency in a Bedrock application is the sum of several components: authentication and API edge time, model queueing, prompt processing, generation, retrieval, reranking, tool calls, agent orchestration, network hops, and client rendering. Optimizing only the model invocation can produce little user-visible improvement when the real delay is a large retrieval query or three sequential agent actions. Amazon Bedrock provides several latency-related options, including streaming APIs, prompt caching, cross-Region inference, inference-profile routing, and a latency-optimized inference feature that AWS currently documents as preview for supported models and Regions. The useful approach…

Read More

Amazon AWS AIP-C01: IAM for GenAI Applications

IAM for generative AI applications is the boundary between “the model can reason about this operation” and “the AWS account actually permits this operation.” Amazon Bedrock, Knowledge Bases, AgentCore, Lambda tools, vector stores, S3 sources, KMS keys, Secrets Manager, and application services can each require different identities and permissions. Collapsing them into one broad execution role makes agent behavior hard to contain and harder to audit. The durable principle is least privilege with separate identities for humans, deployment automation, application runtime, retrieval, and high-impact tools. AWS Identity and Access Management…

Read More

Amazon AWS AIP-C01: From GenAI Prototype to Production on AWS

A generative AI prototype proves that a model can produce a useful response. A production system has to prove far more: the right user can access it, the right model and prompt are deployed, data is governed, retrieval is current, tools are authorized, latency is acceptable, cost is bounded, failures are observable, releases are reproducible, and the application can recover when a dependency fails. AWS provides managed services that reduce infrastructure work, but the production transition is still an application-engineering program. Bedrock handles model access and managed GenAI capabilities; API…

Read More

Amazon AWS AIP-C01: Cost Control for Bedrock Workloads

Amazon Bedrock cost is the result of workload shape, not one advertised token price. Model choice, input and output length, retrieval, reranking, agents, tool loops, cross-Region routing, prompt caching, provisioned capacity, evaluation jobs, embedding generation, and supporting AWS services can all contribute to the cost of one successful business task. The useful FinOps unit is therefore not “cost per API call.” It is cost per completed outcome: resolved support case, generated report, accepted code change, processed document, or completed agent workflow. Bedrock gives teams several technical levers, but those levers…

Read More

Amazon AWS AIP-C01: Chunking Strategies for Bedrock

Chunking is one of the most consequential design choices in a Bedrock Knowledge Base because the retriever does not search entire documents as one unit. During ingestion, Bedrock parses content, splits it into chunks, converts those chunks into embeddings, and writes the vectors to the configured store while preserving a mapping back to the source. The chunk becomes the basic retrieval unit the application later asks the model to reason over. Amazon Bedrock currently supports default, fixed-size, hierarchical, semantic, and no-chunking choices for text, with multimodal content handled differently according…

Read More

Amazon AWS AIP-C01: Caching Patterns for GenAI on AWS

Caching in generative AI is not one technique. An AWS application can cache repeated prompt prefixes at the Amazon Bedrock model layer, cache retrieval or tool results in an application store, cache rendered API responses where semantics allow it, and reuse static reference context so the model does not repeatedly process the same tokens. Each cache has a different freshness, privacy, and invalidation model. Amazon Bedrock currently provides prompt caching for supported models. Explicit prompt caching lets applications define cache checkpoints for reusable prompt content, while some model families also…

Read More

Amazon AWS AIP-C01: CI/CD for GenAI on AWS

CI/CD for generative AI on AWS has to version more than application code. Production behavior can change through prompts, foundation-model identifiers, inference profiles, Guardrails, Knowledge Bases, agent instructions, action groups, embedding models, retrieval settings, evaluation datasets, Lambda tools, and infrastructure. A release process that tracks only the web application can leave the most important AI behavior unreviewed. Amazon Bedrock Prompt management provides versioned prompts and variants, Bedrock resources are available through APIs and infrastructure-as-code patterns, and AWS delivery services can automate deployment. The engineering goal is one evidence-backed release path…

Read More

Amazon AWS AIP-C01: Bedrock Model Evaluation

Amazon Bedrock evaluations provide several ways to compare model and RAG behavior with repeatable evidence. Current Bedrock supports programmatic model evaluations, human-based evaluation jobs, model evaluation with an LLM as judge, and LLM-based evaluation of knowledge bases or external RAG sources. The platform can score built-in or custom metrics and store evaluation datasets and results in Amazon S3. The important engineering principle is that model evaluation should answer a product question: Which model meets the quality target? Did the new prompt reduce factual errors? Does the knowledge base retrieve the…

Read More

Amazon AWS AIP-C01: Bedrock Knowledge Bases in Practice

Amazon Bedrock Knowledge Bases provides a managed retrieval layer for RAG applications. It can ingest supported data sources, create or use embeddings, store and retrieve chunks through supported vector stores, apply metadata filtering and reranking, and combine retrieval with generation through Bedrock runtime APIs. Newer capabilities also include structured data stores that translate natural-language questions into SQL and agentic retrieval that can decompose complex questions into subqueries. The product simplifies plumbing, but retrieval quality still depends on source authority, parsing, chunking, metadata, permissions, embeddings, reranking, and evaluation. A knowledge base…

Read More

Amazon AWS AIP-C01: Bedrock Agents and Tool Use

Amazon Bedrock Agents turn a foundation model into an orchestrator that can interpret a user request, decide which action or knowledge source is relevant, gather missing information, call tools, and return a final response. The architecture is powerful because the agent can bridge natural language and business APIs. The risk is that model reasoning now influences real systems, which makes tool design, identity, validation, user confirmation, and observability first-class engineering concerns. Current Bedrock Agents documentation supports action groups backed by Lambda functions or by return-of-control patterns where the application handles…

Read More

Amazon AWS AIP-C01: Amazon Bedrock Model Selection

Amazon Bedrock model selection is no longer a simple choice between a few text models. The Bedrock catalog includes foundation models from multiple providers, model families with different modalities and context windows, multiple API compatibility options, in-Region and cross-Region inference, inference profiles, on-demand and provisioned capacity patterns, and model lifecycle differences. AWS’s current Bedrock guidance recommends choosing by capability, endpoint and API compatibility, Region, data-residency needs, cost, and throughput. For new applications, AWS recommends the bedrock-runtime endpoint. Bedrock can also list available foundation models and inference profiles programmatically so applications…

Read More

Amazon AWS AIP-C01: API Gateway for GenAI Applications

Amazon API Gateway can act as the governed front door for a generative AI application built on Amazon Bedrock. Instead of allowing each client to invoke foundation models directly, an API layer can enforce authentication, tenant isolation, quotas, throttling, request validation, Web Application Firewall controls, lifecycle versioning, and observability before the request reaches the Bedrock runtime. AWS has published an AI-gateway architecture pattern using API Gateway in front of Bedrock for these controls. API Gateway also supports response streaming for REST API proxy integrations, which can improve time to first…

Read More

Microsoft SC-500: Zero Trust for Azure Workloads

Zero Trust for Azure workloads means applying three principles—verify explicitly, use least privilege, and assume breach—to every user, workload, data path, and administrative action. It is not a product or a network topology. It is a way of designing Azure so trust is granted for a specific request and scope rather than inherited permanently from location or account history. Microsoft’s current Azure Zero Trust guidance maps those principles to Entra authentication and Conditional Access, Azure RBAC and just-in-time privilege, managed identities, segmentation, encryption, continuous monitoring, and resilient recovery. The architecture…

Read More

Microsoft SC-500: Threat Modeling Cloud and AI Systems

Threat modeling is the practice of understanding how a system works, where trust changes, what an attacker might abuse, and which controls reduce the resulting risk before the system reaches production. Cloud and AI systems need this discipline because they combine identities, network paths, data stores, third-party services, models, tools, agents, prompts, and automated actions into one data flow. Microsoft’s current agent security guidance provides reference data flows and threat-modeling approaches for agent systems. It emphasizes mapping prompts, orchestrators, tools, knowledge sources, memory, identities, and external systems so security teams…

Read More