Skip to content
BytePatterns

AIP-C01 · Domain 2: Implementation and Integration · 26% of the exam

Task 2.1: Implement agentic AI solutions and tool integrations.

Building agents that act safely: AgentCore Runtime, Memory, Gateway and Identity, MCP tools, stopping conditions and limits, multi-agent coordination and human review steps.

Study it

  • Agents on AgentCore: Runtime sessions, Memory, Gateway tools, Identity and Policy

    Partly covered by: Agents and Tools, The Tool-Use Loop

  • Keeping agents in bounds: iteration limits, timeouts, human approval and multi-agent coordination

    Partly covered by: Agents and Tools

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

A software company offers a coding agent to its customers. During a conversation the agent writes files, runs commands and holds OAuth tokens for the customer's repositories, and a conversation can last up to three hours with gaps of a few minutes between messages. Security requires that no customer's files, memory or credentials can ever be reached from another customer's conversation, and the team does not want to manage servers. Which hosting approach meets these requirements?

  1. ACreate an Amazon EKS namespace for each customer and schedule the agent pods with network policies between namespaces
  2. BHost the agent on Amazon Bedrock AgentCore Runtime and give each customer conversation its own runtimeSessionId
  3. CRun the agent as an Amazon ECS service on AWS Fargate and keep each conversation's state in the memory of the running tasks
  4. DRun the agent as one AWS Lambda function and keep each conversation's files in the shared /tmp directory between invocations
Show the answer and why
  • ACreate an Amazon EKS namespace for each customer and schedule the agent pods with network policies between namespaces

    Incorrect

    Namespaces with network policies can separate tenants, but the team would operate the cluster, and isolation is per customer rather than per conversation.

  • BHost the agent on Amazon Bedrock AgentCore Runtime and give each customer conversation its own runtimeSessionId

    Correct

    Each AgentCore Runtime session runs in a dedicated microVM with isolated CPU, memory and filesystem, keeps context across invocations for up to 8 hours, and is sanitized when it ends. It is serverless.

  • CRun the agent as an Amazon ECS service on AWS Fargate and keep each conversation's state in the memory of the running tasks

    Incorrect

    Tasks in one service serve many customers at once, so in-memory state and files from different conversations share the same task, which breaks the isolation requirement.

  • DRun the agent as one AWS Lambda function and keep each conversation's files in the shared /tmp directory between invocations

    Incorrect

    Lambda is serverless, but an execution environment can be reused by different callers, so shared /tmp storage gives no per-customer isolation, and an invocation is limited to 15 minutes.

Agents differ from stateless functions: they keep state for a long time and perform privileged actions with user credentials. AgentCore Runtime gives every session its own microVM and terminates and sanitizes it at the end, which is the isolation boundary this scenario needs. The application must still map users to session IDs, because AgentCore does not enforce that mapping.

Question 2 · choose 1

A retail agent must keep the thread of the current conversation even when the user returns after an hour, and must remember durable facts about each shopper, such as preferred sizes and brands, in later conversations. The token cost of each request must not grow with the length of the shopper's history, and one shopper's memories must never be returned for another. Which design meets these requirements?

  1. ARecord turns as AgentCore Memory events and add a user preference strategy whose namespace includes the actor ID
  2. BIngest the chat transcripts into an Amazon Bedrock knowledge base and retrieve the most similar transcripts for each new message
  3. CKeep the conversation and the preferences in the AgentCore Runtime session so that the microVM holds them between visits
  4. DStore the full message history of every shopper in an Amazon DynamoDB table and send the complete history with each request
Show the answer and why
  • ARecord turns as AgentCore Memory events and add a user preference strategy whose namespace includes the actor ID

    Correct

    Short-term memory stores raw events for a session, and a long-term strategy extracts preferences asynchronously into memory records under a namespace that includes the actor ID, so the agent retrieves only what is relevant for that shopper.

  • BIngest the chat transcripts into an Amazon Bedrock knowledge base and retrieve the most similar transcripts for each new message

    Incorrect

    A knowledge base answers what authoritative sources say. Without per-shopper scoping, similar transcripts from other shoppers could be retrieved, and preferences are not extracted.

  • CKeep the conversation and the preferences in the AgentCore Runtime session so that the microVM holds them between visits

    Incorrect

    Runtime session state is ephemeral and lasts only as long as the session's microVM, so preferences would be lost between visits.

  • DStore the full message history of every shopper in an Amazon DynamoDB table and send the complete history with each request

    Incorrect

    DynamoDB is a good store for conversation history, but sending the complete history every time makes token cost grow with each shopper's past, which the requirements forbid.

Agent memory has two layers. Short-term memory replays the current conversation; long-term memory strategies extract durable facts, such as user preferences, and namespaces scoped by actor keep each user's records separate. Retrieving only relevant records keeps prompts small.

Question 3 · choose 2

A company runs a customer service agent on the Amazon Bedrock AgentCore harness. The agent can call a refund tool exposed through an AgentCore Gateway. Red-team testing showed that a crafted message can talk the agent into issuing refunds above the 500 USD limit, and that one test conversation looped through tool calls for 40 minutes. The company wants the limit enforced deterministically outside the agent's reasoning, and every invocation stopped after at most 20 reasoning cycles or 10 minutes. Which actions should the developer take? (Choose TWO.)

  1. AAttach a policy engine to the gateway with a Cedar policy that forbids the refund tool when context.input.amount exceeds 500
  2. BSet maxIterations to 20 and timeoutSeconds to 600 in the harness configuration
  3. CAdd a denied topic called refunds to an Amazon Bedrock guardrail that is applied to the agent's model
  4. DAdd a sentence to the system prompt that forbids refunds above 500 USD under any circumstances
  5. ESet reserved concurrency on the Lambda function behind the refund tool to limit how many refunds can run
Show the answer and why
  • AAttach a policy engine to the gateway with a Cedar policy that forbids the refund tool when context.input.amount exceeds 500

    Correct

    Policy in AgentCore evaluates every tool call at the gateway, outside the agent's code, and Cedar conditions can test tool arguments such as the refund amount, so no prompt can bypass it.

  • BSet maxIterations to 20 and timeoutSeconds to 600 in the harness configuration

    Correct

    The harness limits cap reasoning and action cycles per invocation and the wall-clock time of a single invocation, which stops runaway loops.

  • CAdd a denied topic called refunds to an Amazon Bedrock guardrail that is applied to the agent's model

    Incorrect

    A denied topic would block conversations about refunds altogether, and it evaluates text, not the arguments of a tool call.

  • DAdd a sentence to the system prompt that forbids refunds above 500 USD under any circumstances

    Incorrect

    Prompt instructions are part of what the attacker manipulated. They are not deterministic enforcement.

  • ESet reserved concurrency on the Lambda function behind the refund tool to limit how many refunds can run

    Incorrect

    Reserved concurrency limits parallel executions, not the amount of a refund or the length of an agent loop.

Controlled autonomy needs boundaries that the model cannot talk its way around. Business limits on tool arguments belong in a policy evaluated at the gateway (default deny, forbid wins), and runaway behavior is stopped by hard limits on iterations, time and tokens.

Question 4 · choose 1

A platform team exposes tools to agents through one Amazon Bedrock AgentCore Gateway. Twelve tools are simple lookups that each finish in under a second and keep no state. One tool searches a 2 GB in-memory index that takes four minutes to load and keeps long-lived database connections. The team wants low operating effort for the simple tools and acceptable latency for the heavy one. How should the team host the tools?

  1. ARun all thirteen tools in one container on a single Amazon EC2 instance and connect the agents to it directly
  2. BImplement all thirteen tools as Lambda functions and add each one to the gateway as a Lambda target
  3. CDeploy each of the thirteen tools as its own AgentCore Runtime agent and route agents to them through HTTP targets on the gateway
  4. DAdd the simple tools as Lambda targets, and run the index tool as an MCP server on Amazon ECS added as an MCP target
Show the answer and why
  • ARun all thirteen tools in one container on a single Amazon EC2 instance and connect the agents to it directly

    Incorrect

    A single instance is a single point of failure that the team must patch and scale, and bypassing the gateway loses its central authorization and tool catalog.

  • BImplement all thirteen tools as Lambda functions and add each one to the gateway as a Lambda target

    Incorrect

    A new Lambda execution environment would reload the 2 GB index, which takes minutes, and database connections would be opened and closed repeatedly.

  • CDeploy each of the thirteen tools as its own AgentCore Runtime agent and route agents to them through HTTP targets on the gateway

    Incorrect

    HTTP targets are proxied without aggregation, so the tools would not appear in one MCP tool list, and running simple lookups as separate agents adds needless overhead.

  • DAdd the simple tools as Lambda targets, and run the index tool as an MCP server on Amazon ECS added as an MCP target

    Correct

    Stateless, short tools fit Lambda targets that the gateway turns into MCP tools. A long-running container keeps the large index loaded and its connections open, and the gateway can aggregate it as an MCP server target.

Match the tool's runtime profile to its host: lightweight stateless tools on Lambda behind the gateway, heavyweight stateful tools in long-running containers exposed as MCP servers. The gateway aggregates MCP targets into one virtual MCP server so agents see a single catalog.

Question 5 · choose 1

An insurer's claims agent must label each claim's fraud risk as low, medium or high before its payout tool can run. Audits show that every model the team tested has its own systematic blind spots, and a wrong "low" label on a fraudulent claim is very costly. A decision may take up to a minute, cost per claim is a secondary concern, and compliance wants uncertain cases decided by a human investigator rather than by a model. Which design best meets these requirements?

  1. AFine-tune the best-performing model on past labeled claims and use its label alone
  2. BHave one model label each claim and send only the claims it labels high to an investigator
  3. CAsk three models from different providers and send any disagreement to an investigator
  4. DCall one model three times at a high temperature and take the majority label
Show the answer and why
  • AFine-tune the best-performing model on past labeled claims and use its label alone

    Incorrect

    Fine-tuning on labeled examples suits teaching one model a specific task. The single model's remaining blind spots would still decide every claim.

  • BHave one model label each claim and send only the claims it labels high to an investigator

    Incorrect

    Reviewing only high labels fits when false alarms are the main concern. A wrong "low" label, the costly error here, would never be reviewed.

  • CAsk three models from different providers and send any disagreement to an investigator

    Correct

    Running independent model calls in parallel and aggregating the outputs programmatically is a documented way to add robustness, and a disagreement between models with different blind spots marks an uncertain case for the human.

  • DCall one model three times at a high temperature and take the majority label

    Incorrect

    Repeated sampling smooths out random variation in one model's answers. All three samples share that model's systematic blind spots.

A model ensemble is worth its cost when single-model errors are expensive and uncorrelated across models. Use agreement as the gate and route disagreement to a person.

Question 6 · choose 1

A team has 12 existing Lambda functions that look up orders, refunds and shipping. It wants agents to discover and call them as MCP tools through one endpoint, without rewriting the functions as MCP servers. What should the team do?

  1. AAdd the functions as Lambda targets of an AgentCore gateway
  2. BPaste each function's code into the agent's system prompt
  3. CRewrite each function as an MCP server on Amazon ECS
  4. DCall the functions from the client and send their results as user messages
Show the answer and why
  • AAdd the functions as Lambda targets of an AgentCore gateway

    Correct

    Gateway turns Lambda targets into tools that agents reach through one MCP endpoint.

  • BPaste each function's code into the agent's system prompt

    Incorrect

    The model cannot execute code from a prompt, and secrets could leak.

  • CRewrite each function as an MCP server on Amazon ECS

    Incorrect

    This is the rewrite the team wants to avoid.

  • DCall the functions from the client and send their results as user messages

    Incorrect

    This bypasses the agent's tool choice and needs custom code for every function.

Gateway targets wrap existing services as tools. Lambda targets are the fastest path for functions you already run.

Question 7 · choose 2

A logistics company wants an agent to book pickups on six carrier websites that have no APIs. The agent must fill in and submit web forms, the company will not operate its own browser fleet, web activity must stay isolated from the company's systems, and auditors need a replay of every action the agent took in each session, stored in the company's own S3 bucket. Which actions should the developer take? (Choose TWO.)

  1. ACreate a custom AgentCore Browser with session recording to the company's S3 bucket
  2. BGive the agent AgentCore Code Interpreter to send HTTP requests to the carrier sites
  3. CUse the AWS managed browser and rely on AWS CloudTrail for the audit trail
  4. DDrive the sessions through the Automation endpoint with a library such as Playwright
  5. ERun headless Chromium in a Lambda function attached to the company's VPC
Show the answer and why
  • ACreate a custom AgentCore Browser with session recording to the company's S3 bucket

    Correct

    AgentCore Browser runs isolated browser sessions in a managed environment. Session recording, available for custom browsers, captures user actions, DOM changes and network events, stores them in your S3 bucket and supports replay.

  • BGive the agent AgentCore Code Interpreter to send HTTP requests to the carrier sites

    Incorrect

    Code Interpreter runs code in a sandbox, which suits calculations and data analysis. It does not drive web pages the way a browser does.

  • CUse the AWS managed browser and rely on AWS CloudTrail for the audit trail

    Incorrect

    The managed browser gives the quickest setup, but session recording is available for custom browsers, and CloudTrail records API calls rather than the actions inside a web page.

  • DDrive the sessions through the Automation endpoint with a library such as Playwright

    Correct

    The Automation endpoint lets the agent navigate, click and fill in forms in the session, and libraries such as Playwright simplify these actions.

  • ERun headless Chromium in a Lambda function attached to the company's VPC

    Incorrect

    A self-built headless browser suits simple scraping. The company would run it itself, it has no built-in replay, and it would put web activity inside the company network.

Agents that must use websites without APIs need a managed, isolated browser. Pick the custom browser when the audit needs recordings in your own bucket.

Question 8 · choose 1

A bank's support assistant calls an Amazon Nova model through the Converse API with four client-side tools: verify_customer, get_balance, list_transactions and open_dispute. Compliance requires the model's first response in every conversation to be a verify_customer request built from the customer's first message, before any other tool runs or any text is shown. Tests show that, despite a rule in the system prompt, the model sometimes calls get_balance first or replies in text. After verification, the model must again choose freely among all four tools. What should the developer do?

  1. ASet toolChoice to any on the first call of each conversation
  2. BName verify_customer in toolChoice on the first call of each conversation
  3. CRestate the verification rule in the system prompt and set temperature to 0
  4. DName verify_customer in toolChoice on every call of the conversation
Show the answer and why
  • ASet toolChoice to any on the first call of each conversation

    Incorrect

    With any, the model must request at least one tool and generates no text, but it may still pick get_balance or another tool first.

  • BName verify_customer in toolChoice on the first call of each conversation

    Correct

    A specific tool in toolChoice makes the model request that tool, and Amazon Nova models support it. Later calls keep the default auto, so the model chooses freely once the customer is verified.

  • CRestate the verification rule in the system prompt and set temperature to 0

    Incorrect

    Firmer wording and a low temperature make responses more consistent, but under the default auto the model still decides whether and which tool to call, so the rule is not guaranteed.

  • DName verify_customer in toolChoice on every call of the conversation

    Incorrect

    Forcing the tool on every call makes each response request verify_customer again, so the model could never move on to the other tools after verification.

Use toolChoice per call: force a specific tool only where a step is mandatory, and let the model choose everywhere else.

Question 9 · choose 1

A platform team wants agents to call the read operations of an AWS service as MCP tools through the company's existing AgentCore gateway. The service's API uses the REST-JSON protocol, and AWS publishes its API model. The team will not write, deploy or run code for this integration, will not write, convert or maintain any other API description, and wants every call signed with the gateway's IAM service role so that the role's policy limits what agents can do. What should the team add to the gateway?

  1. AA Lambda target whose function calls the service with the AWS SDK
  2. BAn OpenAPI target described for the API, signed with SigV4 by the role
  3. CAn MCP server target for a server on AgentCore Runtime that wraps the API
  4. DA Smithy model target built from the service's model, using the role
Show the answer and why
  • AA Lambda target whose function calls the service with the AWS SDK

    Incorrect

    Lambda targets run custom code that implements each tool, described by a tool schema. The team would have to write and maintain that function.

  • BAn OpenAPI target described for the API, signed with SigV4 by the role

    Incorrect

    OpenAPI targets turn MCP calls into HTTP requests defined by an OpenAPI specification of the API. Writing or converting that description is the work the team has ruled out.

  • CAn MCP server target for a server on AgentCore Runtime that wraps the API

    Incorrect

    MCP server targets connect the gateway to an existing MCP server. The team would have to write that server and deploy it.

  • DA Smithy model target built from the service's model, using the role

    Correct

    Smithy model targets suit AWS services: the gateway turns MCP requests into calls to the API that the model defines, and built-in models exist for common AWS services. REST-JSON is the supported protocol, and the gateway service role is a supported outbound authorization.

Match the gateway target to what already exists: AWS service APIs come with Smithy models, so a Smithy target needs no code and no hand-written API description.

Practise domain 2 →Practise all domains →