← Back to all posts
Build in Public

AWS AI Practitioner — Day 1: Environment & Core Concepts

Learn: confirm AWS CLI access, create an S3 bucket for datasets, launch a SageMaker notebook instance (or Studio). Review high-level ML lifecycle (data, train, deploy, monitor).

Hands-on: upload a small CSV to S3 and open it in a notebook.

Practice question (AWS-style):

Q1: Which IAM principle should you follow when creating a role for SageMaker notebooks?

A) Grant full AdministratorAccess to avoid permission errors B) Use least-privilege, granting only S3 read/write and SageMaker access C) Share your personal user credentials with the notebook D) Disable IAM for speed

Answer: B — follow least-privilege and restrict to required resources.

Daily Practice Questions (new)

Q1: What CLI command lists S3 buckets?

A) aws s3 ls B) aws s3 cp C) aws ec2 describe-instances D) aws iam list-users

Answer: A — aws s3 ls lists buckets and objects.

Q2: How do you check your active AWS CLI profile?

A) aws configure list B) aws sts get-caller-identity C) aws iam get-user D) aws s3 ls

Answer: A — aws configure list shows current profile and config.

Q3: What file commonly stores AWS CLI credentials locally?

A) ~/.aws/credentials B) /etc/passwd C) ~/.ssh/id_rsa D) ~/.gitconfig

Answer: A — ~/.aws/credentials stores profile credentials.

Q4: Which SageMaker offering provides managed notebooks?

A) SageMaker Studio B) EC2 only C) S3 D) Lambda

Answer: A — SageMaker Studio/Notebook Instances are managed notebook services.

Q5: Why use a dedicated S3 bucket per project?

A) Isolation and access control B) To increase latency C) To avoid billing D) To disable encryption

Answer: A — per-project buckets simplify permissions and isolation.

Q6: What is an AWS region?

A) Geographic area for hosting resources B) A single data center room C) A local network switch D) A client machine

Answer: A — regions are geographic areas containing AWS zones.

Q7: How do you verify SageMaker can access an S3 bucket?

A) Read from notebook with boto3 B) Ping the S3 URL in browser C) Use ssh into S3 D) Check EC2 instance tags

Answer: A — attempt a boto3 read to confirm permissions.

Q8: What is the principle of least-privilege?

A) Grant only necessary permissions B) Grant Admin to everyone C) Share credentials widely D) Disable IAM controls

Answer: A — least-privilege limits permissions to what’s needed.

Q9: Why avoid using the root account for daily tasks?

A) It’s overly privileged and risky B) It is cheaper C) It runs faster D) It has limited API access

Answer: A — using root increases risk of accidental wide-impact changes.

Q10: Which service stores secrets such as DB passwords?

A) AWS Secrets Manager B) S3 Standard-IA C) CloudWatch D) Route 53

Answer: A — Secrets Manager is designed for storing secrets securely.

Review Questions (previous lessons)

Q1: What are the main stages of the ML lifecycle?

A) Data, train, deploy, monitor B) Design, paint, ship, sell C) DNS, IP, MAC, ARP D) Plan, throw, ignore

Answer: A — core ML lifecycle is data → train → deploy → monitor.

Q2: Where should durable model artifacts be stored?

A) S3 B) /tmp only C) Browser cache D) Console output

Answer: A — S3 provides durable storage for artifacts.

Q3: What is a simple health check for an endpoint?

A) HTTP 200 response for a test input B) Deleting the endpoint C) Changing DNS D) Increasing instance size

Answer: A — a 200 response for a known input indicates basic health.

Q4: Which service is commonly used for logs and metrics on AWS?

A) CloudWatch B) Route 53 C) S3 Glacier D) IAM

Answer: A — CloudWatch handles logs and metrics.

Q5: Why version artifacts like models?

A) Reproducibility and rollback B) To increase latency C) To hide files D) To cost more

Answer: A — versioning helps reproduce and roll back to known states.

Q6: What is a typical Batch Transform use-case?

A) Scoring historical datasets in bulk B) Real-time chatbots C) DNS routing D) IAM management

Answer: A — Batch Transform is for bulk/offline scoring.

Q7: Which option provides low-latency serving on AWS?

A) SageMaker real-time endpoints B) S3 static website C) Route53 health checks D) CloudTrail

Answer: A — real-time endpoints are for low-latency inference.

Q8: How can you invoke an endpoint from the command line?

A) Use curl or an AWS SDK script B) Edit DNS records C) Push a commit D) Change IAM policies

Answer: A — curl or SDK calls send test requests to endpoints.

Q9: What error indicates missing permissions when accessing S3?

A) AccessDenied exceptions B) 200 OK C) 302 Redirect D) 1:1 mapping

Answer: A — AccessDenied denotes insufficient permissions.

Q10: What should you do before running paid/cloud jobs?

A) Estimate costs and set limits/alerts B) Ignore billing C) Run indefinitely D) Use root account only

Answer: A — estimate costs and configure budgets/limits.