GregLab | Exam Prep

Security, Identity, and Compliance

IAM

AWS Identity and Access Management controls authentication and authorization to AWS APIs through users, roles, policies, and federation. Least-privilege IAM is the decisive boundary for model invocation, data access, and agent tools.

Key points

  • Identity and resource policies combine with explicit-deny precedence
  • Roles provide temporary credentials for workloads and federated principals
  • Condition keys can restrict resources, networks, tags, models, and request context where supported

When to use it

  • Limit an application role to approved Bedrock models
  • Give each agent action only the data permissions it requires

Exam tips

  • Use IAM for AWS API authorization; prompts and Guardrails cannot enforce resource access
  • Test policies with real resource ARNs and remember that service-linked execution roles may also require permission

Free AWS Certified Generative AI Developer - Professional prep

Build focused AIP-C01 quizzes from skill areas, topics, and product references.

Practice with exam-style multiple-choice and multiple-response questions, clearly labeled supplemental exercises, score breakdowns, explanations, and a compact reference for this lane's official exam domains.

Build a quiz

Exam Weights

Quiz builder

Choose your practice set

Mode

Exam fidelity: AWS lists multiple choice and multiple response for this exam. Ordering, matching, and case-study items are supplemental learning exercises; their results stay in overall study accuracy but do not count toward exam-style accuracy. Difficulty labels describe this site's scenario complexity, not an AWS-published question rating.

Reference

AIP-C01 topics and reference map

Study links

AIP-C01 resources