Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free The Open Group TOGAF Enterprise Architecture Combined Part 1 and Part 2 Exam OGEA-103 Exam Questions

Page: 1 / 14 Total 200 questions

Want more questions? Get Premium Access.

Question 1

Which of the following are interests important to the stakeholders in a system?

Correct Answer: C. Concerns
Explanation:

Concerns are interests important to the stakeholders in a system. They are used to identify and classify the system's stakeholders and to guide the selection of viewpoints for the architecture description. Reference: The TOGAF Standard | The Open Group Website, Section 3.2.1 Architecture Viewpoints


Question 2

Full Scenario

You are employed as an Enterprise Architect within the Enterprise Architecture (EA) team at a clinical research and health technologies company. The company has multiple divisions. Your team works within the healthcare division.

The healthcare division is always creating new products and needs to show the effectiveness and safety of the products. This happens in a set of clinical trials that satisfy the legal requirements of the relevant health authorities. The clinical trials are undertaken by the division's research laboratories at multiple facilities worldwide. At any time, there are many clinical trials happening. In addition to internal research and development activities, the healthcare division is also involved in publicly funded research projects with industrial and academic partners.

Your team is working on an architecture project to develop a secure system that will allow the healthcare researchers to share information more easily about their clinical trials. It will make working together easier across the organization. This system will also allow secured collaboration with external partners.

The EA team uses the TOGAF Architecture Development Method with adaptations required to support healthcare production methods and laboratory procedures. Due to the highly sensitive nature of the information that is managed, special care has been taken to ensure that each architecture domain considers the privacy and safety concerns.

The EA team has been instructed to minimize disruptions to the trials and to gradually introduce the new system.

The company has an established EA practice and has adopted the TOGAF standard for use in its architecture work. The EA practice is federated, which allows some interoperability and information sharing between the divisions yet permits partially independent activity. The Vice President of the healthcare division is the sponsor of the Enterprise Architecture activity for your EA team.

As part of introducing the new system, how would you go about breaking down the project into work packages?

Based on the TOGAF standard which of the following is the best answer?

Correct Answer: B. Create an Implementation Factor Catalog to indicate actions and constraints. Draw up a matrix with architecture domains and gaps. For each gap, classify solutions as new development, purchased, or existing product. Group similar activities into work packages, identify dependencies, and regroup them into Capability Increments scheduled across Transition Architectures.
Explanation:

In TOGAF, the process of breaking down an initiative into work packages must be grounded in a structured evaluation of gaps, solutions, dependencies, constraints, and implementation factors. Option B precisely follows this guidance. It begins by producing an Implementation Factor Catalog, which is a TOGAF artifact used to record business, technical, regulatory, organizational, and risk considerations that influence implementation. This is especially relevant in the scenario because clinical trials operate under strict regulatory controls, highly sensitive data, and complex coordination across multiple research sites.

Next, Option B calls for creating a gap matrix comparing baseline and target architectures across domains. For each gap, TOGAF requires classification of solution approaches: new development, purchased solution, or reuse of existing components. This aligns directly with the Solutions Continuum and the practice of forming Solution Building Blocks. Grouping similar activities into work packages is also textbook ADM practice, ensuring traceability from architecture gaps into actionable implementation components.

Furthermore, Option B incorporates dependencies analysis and restructures work packages into Capability Increments, which is the TOGAF-recommended method for incremental delivery and Transition Architectures. This matches the scenario's requirement for gradual rollout to minimize disruption to ongoing clinical trials.

Thus, Option B fully reflects the TOGAF standard for structured work package definition.


Question 3

Please read this scenario prior to answering the question.

You are employed as an Enterprise Architect at a healthcare company. The company operates over 250 hospitals and is dedicated to transforming healthcare with new ideas and advancements. The company has multiple divisions including surgery centers, freestanding emergency departments, urgent care clinics, and physician practices. They also develop and supply a range of products and services, many with specialized systems and clinical needs.

The company's Enterprise Architecture (EA) department has been operating for several years and has mature, well-developed architecture governance and development processes following the TOGAF standard. The Chief Information Officer (CIO) is the sponsor of the Enterprise Architecture program.

Healthcare is a highly controlled sector, and the company must maintain robust security practices to keep patient information private and prevent data breaches. The company shares electronic health records with multiple providers and has standardized its medical coding for billing and reporting.

Many of the company's rivals have begun using Artificial Intelligence (AI) in their operations, and the indications are that this will be transformative for healthcare delivery. This is something the EA department has been interested in for a while, and they had recently submitted an Architecture Change Request which was approved. As a result, the CIO has approved a Request for Architecture Work to implement AI-based solutions in the company.

The project has been established and you have been assigned to work on it. Stakeholders, concerns, and business requirements have been identified. The stakeholders have made it clear that timely implementation of changes can be life-critical, and that changes should be focused on improving patient outcomes. They also have a concern about disruption due to the changes and require the systems to preserve clinical data access and maintain critical life-support systems during any outages.

The scope of what is inside and what is outside the architecture efforts has now been confirmed. Your task is to revisit and review the Architecture Principles, as they form part of the constraints on architecture work.

The EA team leader has asked you to explain which Architecture Principles are most relevant for this project.

Based on the TOGAF standard, which of the following is the best answer?

(Note: You should assume the company follows the example set of Architecture Principles that are provided in the TOGAF standard, ADM Techniques, Architecture Principles chapter.)

Correct Answer: D. Common Vocabulary and Data Definitions is essential for standardized medical coding and cross-provider data sharing. This ensures the solutions will properly interpret clinical data consistently across divisions. Data Security is critical to protect patient information aligned with the regulations. It ensures data integrity and system availability for critical care. Requirements-Based Change ensures changes respond to business and clinical needs, supporting changes being driven by clinical requirements.
Explanation:

Option D most precisely reflects the TOGAF example Architecture Principles and aligns directly with the explicit constraints described in the scenario.

The healthcare environment described is highly regulated, data-sensitive, and operationally life-critical. The principle Common Vocabulary and Data Definitions is fundamental because the organization shares electronic health records across providers and relies on standardized medical coding. For AI-based systems to function correctly and safely, consistent interpretation of clinical data across divisions is mandatory.

The principle Data Security directly addresses the requirements for privacy, prevention of breaches, regulatory compliance, integrity of patient records, and continuous availability of systems that support life-critical operations. In healthcare, availability is not merely operational---it is safety-related.

The principle Requirements-Based Change ensures that architecture decisions are driven by validated business and clinical requirements. The scenario clearly emphasizes patient outcomes, life-critical timing, and minimal disruption. This principle ensures AI adoption is justified by measurable clinical and business needs rather than by competitive pressure alone.

The other options contain partially relevant principles but do not collectively address clinical data consistency, regulatory protection, safety, and requirement traceability as comprehensively as Option D.

Therefore, according to TOGAF Architecture Principles guidance, Option D is the best answer.


Question 4

Full Scenario

You are employed as an Enterprise Architect in an Enterprise Architecture (EA) team at a food production and distribution company. The main goal of the company is to increase profit while meeting the needs of consumers for its products. Its customers want food that is produced sustainably, safely, and transparently, while reducing environmental impact.

The company has an Enterprise Architecture practice based on the TOGAF standard, using it as the method and guiding framework. The Chief Information Officer (CIO) is the sponsor of EA practice.

The business is a highly mechanized agricultural operation where business capabilities, including planting, harvesting, processing, packaging, and distribution, rely heavily on technology and machinery. The use of EA has enabled the decision makers to have valuable insights into the different aspects of the business.

The warmer climate has led to less successful farming, and the company is growing fewer crops than before. Also, prices for energy, feed, fuel, and fertilizer have gone up. This has caused a big drop in earnings. Due to the rising costs and lower profits, the company has been unable to do as much to help the environment. It especially has struggled to reduce its carbon emissions.

In response to the situation, the Chief Executive Officer (CEO) has decided that big changes are needed, that will lead both to improved crop production and profitability. They must look to all aspects of the business. This includes looking at the mix of crops to mitigate for the change in climate. The company will also cease to process its own crops and will sell off its processing facilities. Thus, the target market will change, and the end-products will be different and more varied. A formal request for architecture change has been approved. At this stage there is no fixed scope, shared vision, or objectives.

What is the best approach for architecture development to realize the CEO's change in direction for the company?

Based on the TOGAF standard which of the following is the best answer?

Correct Answer: C. The team should produce a new Request for Architecture Work leading to development of a new Architecture Vision. The trade-off method should be applied to identify and select an architecture satisfying the stakeholders. For an efficient change the EA team should be aligned with the organization's planning, budgeting, operational, and change processes.
Explanation:

In TOGAF, when an enterprise undergoes a significant strategic shift---particularly one initiated by executive leadership without a clearly defined scope, vision, or objectives---the correct starting point is always Phase A: Architecture Vision, and only after a formal Request for Architecture Work is created or updated. The scenario explicitly states that the CEO has approved a request for architecture change but has not defined scope, constraints, or direction. This aligns precisely with TOGAF guidance that Phase A must establish the high-level vision, stakeholder concerns, business drivers, and initial requirements before moving into the detailed architecture development phases (B, C, D).

Answer choice C reflects this: it requires producing a new Request for Architecture Work and developing a new Architecture Vision, which is the foundational step for any enterprise-wide transformational effort. TOGAF also requires application of the trade-off method to balance stakeholder needs in the Vision phase before detailed architectures are designed.

Choices A and D incorrectly assume architecture definition can begin without a clear approved vision. Choice B focuses solely on Technology Architecture, which contradicts TOGAF's requirement that Business Architecture must lead the effort during major transformation.

Thus, the only answer compliant with TOGAF ADM is C.


Question 5

Please read this scenario prior to answering the question.

You are employed as an Enterprise Architect within an Enterprise Architecture (EA) team at an environmental agency. The agency has multiple divisions, and is responsible for overseeing environmental protection, regulation, and conservation efforts.

The agency has a well-established EA practice and follows the TOGAF standard as its method for architecture development. Along with the EA program, the agency also uses various management frameworks, including business planning, project/portfolio management, and operations management. The EA program is sponsored by the Chief Information Officer (CIO), who has actively promoted architecting with agility within the EA department as the preferred approach for projects.

The agency is preparing itself for a world where Artificial Intelligence (AI) is widely adopted. As a result, the agency is looking to determine the impact and role that AI will play moving forward.

The CIO has approved a Request for Architecture Work to look at how AI can be used for services across the agency. She has noted that digital platforms will be a priority for investment in order to scale the planned AI applications. Using AI to automate tasks and make things run smoother is seen as a big advantage. Process automation, and improved efficiency from manual, repetitive activities has been identified as the key benefits of applying generative AI to their agency's business. This will include back-office automation, for example, for help center agents who receive hundreds of email inquiries. This should also improve services for their customers by making them more efficient and personalized, tailored to each individual's needs.

Many of the agency leaders are worried about relying too much on AI. Some leaders think their employees will need to learn new skills. Some employees are worried they might lose their jobs to AI. Other leaders worry about security and cyber resilience in the digital platforms needed for AI to be successful.

Refer to the scenario.

The EA team leader has asked how to address the concerns, and how to manage the risks of a new architecture for the project.

Based on the TOGAF standard, which of the following is the best answer?

Correct Answer: D. You recommend an assessment of the power, influence, and interest of key individuals affected by the project. This includes documenting the positions, concerns, issues, and cultural factors of each interest group. This information will shape how the architecture is presented and explained. The concerns and relevant views can be defined for each group and recorded in the Architecture Vision document. The requirements for addressing risk should be recorded in the Architecture Requirements Specification and checked through regular assessments and feedback.
Explanation:

Option D is the best answer because it most closely follows the TOGAF guidance for Phase A -- Architecture Vision, where stakeholder management and risk identification are fundamental activities. The scenario emphasizes multiple stakeholder concerns, including AI adoption, workforce impact, security, cyber resilience, and organizational change. TOGAF recommends performing stakeholder analysis by assessing each stakeholder's power, influence, interest, concerns, issues, and cultural considerations. This information is then used to determine appropriate viewpoints, communications, and architecture views.

TOGAF also requires that stakeholder concerns be reflected in the Architecture Vision, which provides a shared understanding of the proposed architecture and demonstrates how stakeholder concerns will be addressed. At the same time, architecture-related risks and the requirements needed to mitigate them should be captured in the Architecture Requirements Specification, where they can be traced and managed throughout the ADM lifecycle. Continuous review and feedback ensure that risks remain visible and that requirements continue to reflect stakeholder needs as the architecture evolves.

Option A incorrectly limits risk management to Security Architecture. Option B includes stakeholder identification and communication but omits TOGAF's emphasis on stakeholder analysis, viewpoints, and formal recording of risks and requirements. Option C incorrectly postpones risk management until Implementation Governance. Therefore, Option D is the answer most closely aligned with the TOGAF Standard.


Question 6

Which of the following describes a purpose of Architecture Principles?

Correct Answer: B. To establish a common understanding of how to control the business in pursuit of strategic objectives
Explanation:

Architecture Principles are general rules and guidelines that inform and support the way in which an organization sets about fulfilling its mission. They reflect a level of consensus among the various elements of the enterprise, and form the basis for making future IT decisions.One of the purposes of Architecture Principles is to establish a common understanding of how to control thebusiness in pursuit of strategic objectives, by providing a framework for evaluating and agreeing on the changes that affect the enterprise's architecture3Reference:3: The TOGAF Standard, Version 9.2, Part III: ADM Guidelines and Techniques, Chapter 23: Architecture Principles : The TOGAF Standard, Version 9.2, Part IV: Architecture Content Framework, Chapter 31: Architecture Principles


Question 7

Which statement best describes the main purpose of the TOGAF Content Framework?

Correct Answer: C. To drive consistency in the outputs when following the ADM.
Explanation:

The TOGAF Content Framework exists to give a detailed model of architectural work products---including deliverables, the artifacts within them, and the architectural building blocks those artifacts represent. The fundamental intent of embedding a Content Framework in TOGAF is to drive greater consistency in the outputs produced when following the Architecture Development Method (ADM). That means regardless of who is doing the architecture work, or in which phase of ADM, the types of outputs, their structure, classification (deliverable artifact building block), naming, and relationships remain consistent across the organisation. This structured model ensures that architecture work is systematic, standardised, and comparable across different projects or cycles. It is not primarily a mechanism for storage (that's the role of the repository), nor is it only about addressing IT concerns or preventing gaps --- its primary purpose is standardising architecture outputs to support clear communication, reuse, and governance across the enterprise


Question 8

Consider the following ADM phases objectives.

Objective:

1.Develop the Target Data Architecture that enables the Business Architecture and the Architecture Vision

2.Develop the Target Business Architecture that describes how the enterprise needs to operate to achieve the business goals

3.Develop a high-level aspirational vision of the capabilities and business value to be delivered as a result of the proposed Enterprise Architecture

4.Identify candidate Architecture Roadmap components based upon gaps between the Baseline and Target Technology Architectures

Which phase does each objective match?

Correct Answer: C. 1C-2B-3A-4D
Explanation:

*Phase A: Architecture Vision

oDevelop a high-level aspirational vision of the capabilities and business value to be delivered as a result of the proposed Enterprise Architecture

oDefine the scope and boundaries of the architecture engagement

oIdentify the key stakeholders and their concerns and expectations

oDefine the Architecture Vision statement and the Architecture Definition Document

oObtain approval and commitment from the sponsors and stakeholders

*Phase B: Business Architecture

oDevelop the Target Business Architecture that describes how the enterprise needs to operate to achieve the business goals

oDefine the Baseline Business Architecture, if not available

oPerform a gap analysis between the Baseline and Target Business Architectures

oDefine candidate roadmap components for the Business Architecture

oResolve impacts across the Architecture Landscape

*Phase C: Information Systems Architecture

oDevelop the Target Data Architecture that enables the Business Architecture and the Architecture Vision

oDevelop the Target Application Architecture that supports the Business Architecture and the Architecture Vision

oDefine the Baseline Data and Application Architectures, if not available

oPerform a gap analysis between the Baseline and Target Data and Application Architectures

oDefine candidate roadmap components for the Information Systems Architecture

oResolve impacts across the Architecture Landscape

*Phase D: Technology Architecture

oDevelop the Target Technology Architecture that enables the Information Systems Architecture and the Architecture Vision

oDefine the Baseline Technology Architecture, if not available

oPerform a gap analysis between the Baseline and Target Technology Architectures

oIdentify candidate Architecture Roadmap components based upon gaps between the Baseline and Target Technology Architectures

oResolve impacts across the Architecture Landscape

Therefore, the correct matching of the objectives and the phases is:

*1C: Develop the Target Data Architecture that enables the Business Architecture and the Architecture Vision

*2B: Develop the Target Business Architecture that describes how the enterprise needs to operate to achieve the business goals

*3A: Develop a high-level aspirational vision of the capabilities and business value to be delivered as a result of the proposed Enterprise Architecture

*4D: Identify candidate Architecture Roadmap components based upon gaps between the Baseline and Target Technology Architectures


Question 9

What can architects present to stakeholders to extract hidden agendas, principles, and requirements that could impact the final Target Architecture?

Correct Answer: D. Architecture Views and Architecture Viewpoints
Explanation:

According to the TOGAF Standard, Version 9.2, anarchitecture viewis a representation of a system from the perspective of a related set of concerns1.It consists of one or more architecture models that demonstrate how the system addresses the stakeholder concerns1.

Anarchitecture viewpointis a specification of the conventions for constructing and using an architecture view to address specific stakeholder concerns1.It defines the perspective, scope, notation, and techniques for creating an architecture view of a system1.

Architects can present architecture views and viewpoints to stakeholders to extract hidden agendas, principles, and requirements that could impact the final Target Architecture, because23:

Architecture views and viewpoints help to communicate and visualize the architecture in a way that is meaningful and relevant to different stakeholders, addressing their specific interests and needs.

Architecture views and viewpoints help to elicit and validate the stakeholder concerns and requirements, ensuring that they are aligned with the business goals and objectives, and that they are consistent and feasible within the architecture context.

Architecture views and viewpoints help to identify and resolve any conflicts, gaps, or trade-offs among the stakeholder concerns and requirements, ensuring that they are balanced and prioritized in the architecture design and decision-making.

Architecture views and viewpoints help to demonstrate and verify the value and benefits of the architecture to the stakeholders, ensuring that they are satisfied and committed to the architecture outcome and governance.

1: The TOGAF Standard, Version 9.2, Chapter 22: Architecture Views, Viewpoints, and Stakeholders

2: The TOGAF Standard, Version 9.2, Chapter 4: Introduction to Part II, Section 4.2: What is an Architecture Framework?

3: The TOGAF Standard, Version 9.2, Chapter 31: Architectural Artifacts, Section 31.1: Basic Concepts


Question 10

Please read this scenario prior to answering the question

You are working as an Enterprise Architect at a large supermarket. The company runs many retail

stores, as well as an online grocery shop. Many of the stores used to remain open 24/7, but the

number has decreased in recent years. Instead, they now focus on fulfilling online orders during

the night.

The company has a mature Enterprise Architecture (EA) practice and uses the TOGAF standard

for its architecture development method. The EA practice is involved in all aspects of the

business, with oversight provided by an Architecture Board with representatives from different

parts of the business. The EA program is sponsored by the Chief Information Officer (CIO).

Each store uses a standard method to track sales and inventory. This involves sending accurate

timely sales data to a central Al-based inventory management system that can predict demand,

adjust stock levels and automate reordering. The central inventory management system is housed

at the company's central data center.

The company has bought a major rival. The Chief Executive Officer believes that a merger will

enable growth through combined offerings and cost savings. The decision has been taken to fully

integrate the two organizations, including merging retail operations and systems. This means that

duplicated systems will be replaced with one standard retail management system. Also, the

company will reduce the number of applications that are used. The CIO expects significant

savings will be achieved by implementing these changes across the newly merged company.

One improvement that the rival has successfully implemented is the use of hand-held devices

within stores, for both customers and staff. This has increased both customer and staff employee

satisfaction due to the time savings this has brought. The CIO has given the go-ahead to roll out

the devices in all stores but has stated that training on how to use the hand-held devices should

be brief because there are a lot of employees, many of whom are part-time.

The Request for Architecture Work to oversee the merger has been approved. The project has

been scoped and you have been assigned to work on it. Your role includes managing the

architecture for the retail stores.

Refer to the scenario

You have been asked to confirm the most relevant architecture principles for the transformation.

Based on the TOGAF Standard, which of the following is the best answer?

[Note: The sequence of the principles listed in each answer does not matter. You should assume

the company follows the set of principles that are provided in the TOGAF Standard, ADM

Techniques, Architecture Principles chapter. You may need to refer to section 2.6 located in ADM

Techniques within the reference text to answer this question.]

Correct Answer: A. Maximize Benefit to the Enterprise, Common Use Applications, Data is an Asset, Responsive Change Management, Technology Independence
Explanation:

Key aspects of the scenario:

Business Objective:

A merger is happening to combine offerings, reduce costs, and achieve operational efficiency.

The goal includes fully integrating retail operations and systems, replacing duplicated systems, and reducing the number of applications used.

Technological Improvements:

A central AI-based inventory system is in place.

Hand-held devices for stores have improved customer and staff satisfaction and increased efficiency.

Scope of Architecture Work:

Integrating the merged systems.

Managing retail architecture to optimize operations.

TOGAF Alignment:

TOGAF principles aim to ensure the architecture supports business transformation effectively while aligning with governance and best practices.

Best answer analysis:

Option 1:

Maximize Benefit to the Enterprise: Aligns with the merger goals of cost reduction and efficiency.

Common Use Applications: Matches the goal to reduce duplicated systems.

Data is an Asset: Central AI system depends on accurate and reliable data.

Responsive Change Management: Necessary to support the transition and manage organizational impacts.

Technology Independence: Encourages selecting flexible, scalable solutions post-merger.

This option comprehensively aligns with the scenario.

Option 2:

Control Technical Diversity: Important but less emphasized than cost reduction and application unification.

Interoperability: Relevant, but less critical compared to principles addressing business value.

Data is an Asset: Relevant.

Data is Shared: Implied in centralized inventory but not directly stated.

Business Continuity: Important but not the main focus here.

This option partially fits but lacks emphasis on business outcomes.

Option 3:

Common Vocabulary and Data Definitions: Indirectly helpful but not central to the transformation.

Compliance with the Law: Always critical, but no explicit legal issues are mentioned.

Requirements-Based Change: General principle but not transformation-specific.

Responsive Change Management: Relevant.

Data Security: Important but not a central concern in the scenario.

This option focuses more on governance and less on merger goals.

Option 4:

Common Use Applications: Relevant to reducing duplicate systems.

Data is an Asset: Relevant.

Data is Accessible: Fits with AI system and handheld devices but is a subset of 'Data is an Asset.'

Ease of Use: Relevant to handheld devices but not a core transformation principle.

Business Continuity: Important but secondary to cost and efficiency.

This option focuses more on usability and accessibility rather than transformation objectives.


Question 11

What concept enables the simultaneous operation of multiple ADM phases?

Correct Answer: A. Iteration
Explanation:

Comprehensive and Detailed In-Depth Explanation from Expert in Enterprise Architecture, guiding in TOGAF and ArchiMate:

TOGAF explicitly allows the ADM to be executed in a non-linear and iterative manner.

Iteration enables:

Multiple ADM phases to be active at the same time

Overlapping work across architecture domains

Incremental refinement of architectures

Agile and responsive architecture development

Why Option A is correct:

Iteration is the TOGAF mechanism that enables simultaneous and repeated execution of ADM phases.

Why the other options are incorrect:

B . Change Management: Controls change, but does not enable parallel ADM execution.

C . Digital Transformation: A business initiative, not an ADM execution concept.

D . Transition Planning: A specific planning activity, not an execution model.


Question 12

Complete the sentence. Risk management involves: risk classification, identification,

Correct Answer: D. assessment, monitoring, mitigation and
Explanation:

In TOGAF's treatment of risk within architecture governance and ADM Guidelines & Techniques, risk management is seen as a continuous process including several phases. First one classifies potential risk types. Then one identifies specific risks. After identification comes assessment (evaluating likelihood and impact), monitoring (tracking over time), mitigation (taking actions to reduce the risk), and related response or treatment options to decide what to do with residual risk. That sequence---classification, identification, assessment, monitoring, mitigation, and response---completes the risk management life cycle. It does not stop at evaluation or reporting; it includes active monitoring, control, and reaction to risks over time.


Question 13

Complete the sentence A business scenario describes______________

Correct Answer: C. business and technology environment in which those problems occur
Explanation:

A business scenario describes business and technology environment in which those problems occur. It provides a realistic context for identifying and addressing business problems and opportunities, as well as their impact on the enterprise's architecture. Reference: The TOGAF Standard | The Open Group Website, Section 3.3.1 Business Scenarios.


Question 14

Please read this scenario prior to answering the question

You are employed as an Enterprise Architect at a technology company, reporting directly

to the Chief Enterprise Architect. The company supplies personnel and delivers cloud-

based solutions to numerous government agencies.

The nature of the business is such that the data and the information stored on the

company systems is the company's major asset and is highly confidential. The company

employees work remotely and need constant access to the company systems, which is

done by the public infrastructure. They use message encryption, secure internet

connections using Virtual Private Networks (VPNs), and other standard security

measures. The company provides computer security awareness training for all its staff.

The Chief Security Officer (CSO) has noted an increase in distributed denial of service

(DDoS) attacks on companies with a similar profile. The CSO understands that even

with thorough preparation, a major attack could stop employees from being able to do

their jobs. This could lead to a large financial loss, damage to the company's reputation

with customers, and employees being unable to work.

A risk assessment has been completed and the company has looked for cyber insurance

that covers such attacks. The price for this insurance is very high. The CTO has decided

not to get cyber insurance to cover such attacks.

The company follows the TOGAF standard as the method and guiding framework for its

Enterprise Architecture (EA) practice. The Chief Technology Officer (CTO) is the sponsor

of the activity. The practice uses an iterative approach for its architecture development.

This has enabled the decision makers to gain valuable insights into the different aspects

of the business

Please read this scenario prior to answering the question

You have been asked to describe the steps you would take to strengthen the current

architecture to improve data protection.

Based on the TOGAF standard which of the following is the best answer?

Correct Answer: B. You would run a planning exercise to assess the business continuityrequirements and analyze the current Enterprise Architecture for gaps. Youcreate a formal change request related to business resilience and maintainingcritical business functions. You would arrange a meeting of the ArchitectureBoard to assess and approve the change request. Once approved you wouldcreate a new Request for Architecture Work to begin an ADM cycle toimplement the changes.
Explanation:

In this scenario, the CTO has not purchased cyber-insurance, the CSO is concerned about increased DDoS risk, and YOU (the EA) are asked ''to describe the steps you would take to strengthen the current architecture to improve data protection.''

Because the company follows the TOGAF standard and uses an iterative ADM cycle, the correct response must:

Start with the risk/continuity concern

Use the formal TOGAF change management process

Lead to a Request for Architecture Work

Initiate a new ADM cycle to update the architecture properly

Ensure Architecture Board governance

Option B is the only answer that matches TOGAF's required process.

Why Option B is correct (TOGAF-aligned)

Option B follows TOGAF's Architecture Change Management (Phase H) process:

Assess the business continuity requirements-- Correct: Phase H requires evaluating change triggers such as new risks, threats, or incidents.-- DDoS risk business continuity concern legitimate architecture change trigger.

Analyze the current architecture for gaps-- Correct: TOGAF Phase H requires assessing whether the current baseline architecture can support required resilience.

Create a formal Change Request-- Exactly correct: Phase H outputs Architecture Change Requests (ACRs) for significant changes.-- ACR includes description, rationale, and impact (in this case: resilience, continuity, and data protection).

Architecture Board reviews/approves the change request-- Correct: All major architecture changes must go through Architecture Governance.

Create a new Request for Architecture Work (RFAW)-- Required when the change is significant and needs a new ADM cycle.-- Strengthening data protection and business continuity DEFINITELY qualifies as a major change.

Begin a new ADM cycle to implement the changes-- Perfectly aligned with TOGAF's iterative approach:Business continuity update Technology Architecture updated security patterns updated Target Architecture.

This is exactly the TOGAF-prescribed method to strengthen an architecture when significant new risks appear.

Therefore, Option B is the correct and TOGAF-compliant answer.

Why the other options are incorrect

A -- Not TOGAF-aligned

Starts with vendors and simulations (not TOGAF-first steps).

No mention of Architecture Board or Change Management.

No Request for Architecture Work.

Gap analysis alone is not the first step for significant architectural risk.

C -- Too narrow and skips TOGAF governance

Jumps straight to modifying the Technology Architecture baseline.

No Change Request, no RFAW, no ADM cycle initiation.

Recommends a solution (''DDoS mitigation at infrastructure level'') before architectural assessment.

D -- Misuses Architecture Compliance Review

Architecture Compliance Reviews check conformity to an existing architecture---not evaluate new risks or design resilience enhancements.

A compliance review is not the correct first step for addressing new threats.


Question 15

Which of the following best describes the purpose of the Gap Analysis technique?

Correct Answer: C. To identify items omitted from the Target Architecture
Explanation:

The purpose of the Gap Analysis technique is similar to the previous question, but with a focus on the Target Architecture. The technique helps to identify the items that are not included or specified in the Target Architecture, such as capabilities, services, components, standards, or technologies. These items may be essential for achieving the vision and goals of the enterprise, or for addressing the stakeholder concerns and requirements. By identifying the items omitted from the Target Architecture, the technique helps to ensure that the architecture is comprehensive, feasible, and realistic.