Skip to content
BytePatterns

AIP-C01 · Domain 2: Implementation and Integration · 26% of the exam

Task 2.3: Design and implement enterprise integration architectures.

Fitting GenAI into an existing estate: event-driven and API integrations, identity federation and least privilege, data that must stay in a jurisdiction, and gateways and pipelines for governed use.

Study it

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

A company's CRM emits a "case created" event for every new support case, up to 3,000 a minute after outages. A GenAI service must summarize each case and write the summary back through the CRM API. The CRM must never wait for the model, summaries may arrive a few minutes late, the model's quota allows about 200 concurrent requests, and failed cases must be kept for later analysis. Which integration meets these requirements?

  1. AHave the CRM call an Amazon API Gateway endpoint backed by a Lambda function that invokes the model and returns the summary in its response
  2. BRoute events through Amazon EventBridge to an SQS queue with a dead-letter queue, read by Lambda with maximum concurrency set
  3. CSend the events directly to a Lambda function that invokes the model, and raise the account concurrency limit for the burst
  4. DStart an AWS Step Functions Express workflow for each event that calls the model and retries until it succeeds
Show the answer and why
  • AHave the CRM call an Amazon API Gateway endpoint backed by a Lambda function that invokes the model and returns the summary in its response

    Incorrect

    This makes the CRM wait for every model call, and bursts of 3,000 requests a minute would hit the model quota directly.

  • BRoute events through Amazon EventBridge to an SQS queue with a dead-letter queue, read by Lambda with maximum concurrency set

    Correct

    EventBridge decouples the CRM, the queue absorbs bursts, the event source mapping's maximum concurrency caps parallel model calls below the quota, and the dead-letter queue keeps cases that keep failing.

  • CSend the events directly to a Lambda function that invokes the model, and raise the account concurrency limit for the burst

    Incorrect

    More Lambda concurrency increases parallel model calls during bursts, which causes throttling instead of smoothing the load.

  • DStart an AWS Step Functions Express workflow for each event that calls the model and retries until it succeeds

    Incorrect

    Thousands of parallel executions still call the model at the burst rate, and unlimited retries amplify throttling during an outage.

Loose coupling for GenAI means the producer never waits and the consumer controls the pace. A queue between EventBridge and the worker absorbs bursts, maximum concurrency keeps calls within the model quota, and a dead-letter queue isolates failures.

Question 2 · choose 1

Analysts in three departments call Amazon Bedrock from notebooks and the AWS CLI. They sign in with the corporate identity provider, and security forbids long-lived credentials. Each department may invoke only the models approved for it, and access must be removed automatically when an employee leaves the company directory. Which approach meets these requirements?

  1. ALet all analysts assume one shared IAM role that allows bedrock:InvokeModel on every model in the account
  2. BCreate an IAM user with access keys for each analyst and attach a policy that lists the department's approved model ARNs
  3. CGenerate a long-term Amazon Bedrock API key for each analyst and store the keys in a shared password vault
  4. DUse IAM Identity Center with the corporate identity provider and a permission set per department scoped to its models
Show the answer and why
  • ALet all analysts assume one shared IAM role that allows bedrock:InvokeModel on every model in the account

    Incorrect

    A shared role cannot restrict departments to their own approved models and breaks least privilege.

  • BCreate an IAM user with access keys for each analyst and attach a policy that lists the department's approved model ARNs

    Incorrect

    Access keys of IAM users are long-lived credentials, and they are not removed when the employee leaves the corporate directory.

  • CGenerate a long-term Amazon Bedrock API key for each analyst and store the keys in a shared password vault

    Incorrect

    Long-term API keys create IAM users and are recommended only for exploration. They are long-lived credentials outside the directory.

  • DUse IAM Identity Center with the corporate identity provider and a permission set per department scoped to its models

    Correct

    IAM Identity Center issues short-term credentials to federated users, permission sets carry the per-department model restrictions, and removing a user from the directory removes access.

Federation plus fine-grained permissions is the enterprise pattern: short-term credentials from IAM Identity Center, permission sets that scope InvokeModel to approved model ARNs, and lifecycle tied to the corporate directory.

Question 3 · choose 1

A manufacturer wants an assistant that answers questions about machine logs at a plant in a country where no AWS Region exists. Regulations require the logs and every prompt and response to stay on the plant's premises, and the operators want the same AWS APIs and tooling that the company uses in the cloud. The assistant will use an open-weight model. Which deployment meets these requirements?

  1. AUse a geographic cross-Region inference profile so that requests stay within the plant's geography
  2. BDeploy the model in an AWS Wavelength Zone of the local telecommunications provider
  3. CCall Amazon Bedrock in the nearest AWS Region over an AWS Site-to-Site VPN connection from the plant
  4. DRun the open-weight model on GPU instances in an AWS Outposts rack installed at the plant
Show the answer and why
  • AUse a geographic cross-Region inference profile so that requests stay within the plant's geography

    Incorrect

    Cross-Region inference routes requests among AWS Regions. No Region exists in that country, and processing would not happen on premises.

  • BDeploy the model in an AWS Wavelength Zone of the local telecommunications provider

    Incorrect

    Wavelength places compute at the edge of a 5G network for low latency to mobile devices. That infrastructure is in the carrier's facilities, not on the plant's premises.

  • CCall Amazon Bedrock in the nearest AWS Region over an AWS Site-to-Site VPN connection from the plant

    Incorrect

    A VPN encrypts the traffic, but prompts and responses would still be processed in the Region, outside the plant.

  • DRun the open-weight model on GPU instances in an AWS Outposts rack installed at the plant

    Correct

    Outposts extends AWS infrastructure and APIs to customer premises, so the model and the data stay on site while the team uses the same tooling as in the Region.

When data may not leave a site and no Region is nearby, AWS Outposts brings AWS-managed compute and the same APIs on premises. Wavelength targets mobile edge latency, and cross-Region inference only moves work between Regions.

Question 4 · choose 1

A company's central platform team wants every internal application to reach foundation models from Amazon Bedrock and from two other providers through one endpoint that uses the providers' usual SDKs. Applications must never hold provider credentials, each team must get its own tokens-per-minute limit, and the same Bedrock guardrails must apply to every call regardless of provider. Which solution requires the least custom code?

  1. AAn Amazon API Gateway REST API with usage plans per team and a Lambda function that calls each provider's API
  2. BA shared Lambda function URL that each team calls and that reads provider keys from AWS Secrets Manager
  3. CAn Amazon Bedrock AgentCore Gateway with inference targets, per-team rate limits and central guardrails
  4. DAn Application Load Balancer with path-based routing to each provider's public endpoint
Show the answer and why
  • AAn Amazon API Gateway REST API with usage plans per team and a Lambda function that calls each provider's API

    Incorrect

    Usage plans throttle requests, not tokens, and the Lambda function would need custom code for every provider, credential and guardrail call.

  • BA shared Lambda function URL that each team calls and that reads provider keys from AWS Secrets Manager

    Incorrect

    Secrets Manager keeps the keys safe, but the function URL gives no per-team token limits and every provider integration is custom code.

  • CAn Amazon Bedrock AgentCore Gateway with inference targets, per-team rate limits and central guardrails

    Correct

    Inference targets turn the gateway into a unified LLM proxy that routes by the model in the request, holds provider credentials, applies guardrails and policy to all calls, and supports token-per-minute rate limits per caller.

  • DAn Application Load Balancer with path-based routing to each provider's public endpoint

    Incorrect

    A load balancer forwards traffic but cannot hold provider credentials, count tokens or apply guardrails.

A GenAI gateway centralizes credentials, limits and safety for model traffic. AgentCore Gateway inference targets provide this as a managed service: one endpoint, model-based routing across providers, token-aware rate limits and guardrails for every call.

Question 5 · choose 1

A manufacturer's on-premises plant servers run nightly jobs that call Amazon Bedrock to summarize shift logs and write the results to Amazon S3. Security forbids long-lived AWS credentials on any server, the servers already hold X.509 certificates issued by the company's own certificate authority, and each plant's servers may use only that plant's S3 prefix. The servers are not EC2 instances and will stay on premises. Which approach meets these requirements?

  1. AAn IAM user for each plant with access keys that are rotated every 90 days
  2. BIAM Roles Anywhere with the company CA as a trust anchor and a role per plant
  3. CA long-term Amazon Bedrock API key for each plant, stored on the servers
  4. DAn instance profile that passes an IAM role to each plant server
Show the answer and why
  • AAn IAM user for each plant with access keys that are rotated every 90 days

    Incorrect

    Access keys are long-term credentials; rotation fits tools that can use nothing else. AWS recommends temporary credentials for workloads, and the rule forbids long-lived ones.

  • BIAM Roles Anywhere with the company CA as a trust anchor and a role per plant

    Correct

    Roles Anywhere gives workloads outside AWS temporary credentials in exchange for X.509 certificates from a registered CA. Certificate fields such as the subject become principal tags that a role's trust policy can match.

  • CA long-term Amazon Bedrock API key for each plant, stored on the servers

    Incorrect

    Long-term Bedrock API keys create an IAM user and are recommended only for exploration, and they are long-lived credentials.

  • DAn instance profile that passes an IAM role to each plant server

    Incorrect

    An instance profile passes an IAM role to an EC2 instance. These servers are not EC2 instances.

Workloads outside AWS can still use roles: trust the company's certificate authority and let certificates, not stored keys, prove identity.

Question 6 · choose 1

An online retailer keeps its 4-million-item product catalog in an Amazon DynamoDB table that order systems update thousands of times a minute. A new shopping assistant needs search over the current catalog in Amazon OpenSearch Service, with filters on price and stock, and changes must become searchable within seconds. The existing items must be loaded first, and the team does not want to write or operate synchronization code. Which approach meets these requirements?

  1. AA DynamoDB Streams trigger that runs a Lambda function to write each change to the index
  2. BA nightly export of the table to Amazon S3 that a knowledge base syncs
  3. CThe DynamoDB zero-ETL integration with OpenSearch Service through OpenSearch Ingestion
  4. DAn AWS Glue job that scans the table every 15 minutes and upserts changed items
Show the answer and why
  • AA DynamoDB Streams trigger that runs a Lambda function to write each change to the index

    Incorrect

    Stream triggers suit custom processing of each change, but the team would write and run that code, and it would still need its own initial load.

  • BA nightly export of the table to Amazon S3 that a knowledge base syncs

    Incorrect

    A nightly export fits data that changes daily. Changes would take up to a day, not seconds, to become searchable.

  • CThe DynamoDB zero-ETL integration with OpenSearch Service through OpenSearch Ingestion

    Correct

    The integration loads an initial snapshot through a DynamoDB export to S3 and then replicates changes from DynamoDB Streams in near real time, as a managed, no-code pipeline.

  • DAn AWS Glue job that scans the table every 15 minutes and upserts changed items

    Incorrect

    Scheduled Glue jobs suit periodic batch transformation. A scan reads every item and consumes read capacity, and 15 minutes misses the target.

Keep a search index in sync with an operational table through a managed integration: an initial snapshot followed by a change stream, with no code to maintain.

Question 7 · choose 1

A telecom partner's augmented reality maintenance app runs on technicians' phones on one carrier's 5G network. A small open-weight vision model that fits on one GPU must interpret camera frames fast enough to update an overlay several times a second. The frames are not regulated data, and traffic from the phones should reach the model inside the carrier's network rather than travel out to an AWS Region. Which deployment meets these requirements?

  1. ARun the model on GPU instances in an AWS Local Zone near the technicians
  2. BHost the model on a SageMaker AI real-time endpoint in the parent Region
  3. CRun the model on EC2 in the parent Region behind AWS Global Accelerator
  4. DRun the model on a GPU instance in a Wavelength Zone of the carrier
Show the answer and why
  • ARun the model on GPU instances in an AWS Local Zone near the technicians

    Incorrect

    Local Zones place compute close to population and industry centers for low latency. They are not deployed inside the carrier's 5G network the way Wavelength Zones are.

  • BHost the model on a SageMaker AI real-time endpoint in the parent Region

    Incorrect

    Real-time endpoints suit interactive, low-latency inference from a Region. Every frame would still leave the carrier network and travel to the Region.

  • CRun the model on EC2 in the parent Region behind AWS Global Accelerator

    Incorrect

    Global Accelerator directs traffic over the AWS global network to endpoints in the nearest Region, which helps internet applications. The model still runs in the Region.

  • DRun the model on a GPU instance in a Wavelength Zone of the carrier

    Correct

    Wavelength deploys AWS compute at the edge of the carrier's network, supports g4dn.2xlarge GPU instances, and a carrier gateway accepts traffic from devices on the carrier network.

Edge choices differ by where the compute sits: Regions, Local Zones near cities, and Wavelength Zones inside a carrier's 5G network for mobile devices.

Question 8 · choose 1

A company sells a summarization API to 30 partner companies through an Amazon API Gateway REST API. Partners already authenticate through a Lambda authorizer that validates their OAuth tokens. Gold partners may send 50 requests per second and 2 million requests a month, and Silver partners 10 per second and 200,000 a month. Limits count requests, not model tokens, they must be enforced before the backend Lambda function runs, and partners must not have to send any new header. What should the developer configure?

  1. AUsage plans per tier, with API keys supplied by the Lambda authorizer
  2. BReserved concurrency for each partner on the backend Lambda function
  3. CA resource policy that allows each partner's source IP addresses
  4. DA DynamoDB counter per partner that the backend function checks
Show the answer and why
  • AUsage plans per tier, with API keys supplied by the Lambda authorizer

    Correct

    Usage plans set throttling and quota limits per API key. With the API key source set to AUTHORIZER, the Lambda authorizer returns the key, so partners send nothing new.

  • BReserved concurrency for each partner on the backend Lambda function

    Incorrect

    Reserved concurrency caps how many requests one function handles at once. One function serves every partner, and it sets no monthly quota.

  • CA resource policy that allows each partner's source IP addresses

    Incorrect

    Resource policies control whether a principal or source can invoke the API. They set no request rates or quotas.

  • DA DynamoDB counter per partner that the backend function checks

    Incorrect

    Custom counters fit limits on model tokens or other units that usage plans do not count. The check runs after the request reaches the backend and needs code.

Per-client request limits on REST APIs come from usage plans. When clients already authenticate through a Lambda authorizer, the authorizer can supply the API key.

Question 9 · choose 1

A company's CRM publishes "case updated" events to an Amazon EventBridge custom event bus, and three consumers subscribe through rules: a GenAI summarizer, a search indexer and an analytics loader. Last month a bad prompt release made the summarizer write poor summaries for six hours. Every call succeeded, so nothing reached a dead-letter queue, and the CRM cannot resend events. For future incidents, the team wants to reprocess any time window of up to 30 days for the summarizer only, without the other consumers receiving duplicates and without building its own event store. What should the team set up?

  1. AA dead-letter queue on the summarizer's target that the team redrives after a fix
  2. BA Firehose stream that copies every event to Amazon S3, plus a replay script
  3. CAn archive on the event bus with 30-day retention, replayed to the summarizer's rule only
  4. DA longer retry policy with a 24-hour maximum event age on the summarizer's target
Show the answer and why
  • AA dead-letter queue on the summarizer's target that the team redrives after a fix

    Incorrect

    A dead-letter queue keeps events that failed to be delivered to a target. These events were delivered and processed successfully.

  • BA Firehose stream that copies every event to Amazon S3, plus a replay script

    Incorrect

    Firehose delivers streaming data to destinations such as Amazon S3, which suits long-term retention for analytics. Replaying from it means building the event store and tooling the team wants to avoid.

  • CAn archive on the event bus with 30-day retention, replayed to the summarizer's rule only

    Correct

    An archive keeps events for a retention period you set, and a replay resends events from a chosen time window to the source bus, optionally to specific rules only.

  • DA longer retry policy with a 24-hour maximum event age on the summarizer's target

    Incorrect

    Retry policies resend events that could not be delivered because of retriable errors. They do nothing for events that were delivered and processed badly.

Plan for reprocessing before you need it: archives let an event-driven integration replay history to one consumer without involving the source system.

Practise domain 2 →Practise all domains →