Skip to main content

OGEA-103 Real Exam Questions

TOGAF Enterprise Architecture Combined Part 1 and Part 2

205 questions available · Page 1 of 21

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

What are the following activities part of?
Risk classification
Risk identification
Initial risk assessment

  1. A

    Security Architecture

  2. B

    Phase A

  3. C

    Phase G

  4. D

    Risk Management

Show answer and explanation

Correct answer: D

Explanation

Risk management is a generic technique that can be applied across all phases of the Architecture Development Method (ADM), as well as in the Preliminary Phase and the Requirements Management Phase2. Risk management involves the following steps1: -Risk identification: This step involves identifying the potential risks that may affect the architecture project, such as technical, business, organizational, environmental, or legal risks. The risks can be identified through various sources, such as stakeholder interviews, workshops, surveys, checklists, historical data, or expert judgment.
-Risk classification: This step involves categorizing the risks based on their nature, source, impact, and priority. The risks can be classified according to different criteria, such as time, cost, scope, quality, security, or compliance. The classification helps in prioritizing the risks and allocating resources and efforts to address them effectively.
-Initial risk assessment: This step involves assessing the likelihood and impact of each risk, and determining the initial level of risk. The likelihood is the probability of the risk occurring, and the impact is the severity of the consequences if the risk occurs. The initial level of risk is the product of the likelihood and impact, and it indicates the urgency and importance of the risk. The initial risk assessment helps in identifying the most critical risks that need immediate attention and mitigation.
References:
1: The TOGAF Standard, Version 9.2 - Risk Management
2: TOGAF ADM:
Top 10 techniques - Part 9: Risk Management

Question 2 Single choice

Consider the following descriptions of deliverables consumed and produced across the TOGAF ADM cycle.

Which deliverables match these descriptions?

  1. A

    1 Architecture Requirements Specification - 2 Request for Architecture Work - 3 Statement of Architecture Work - 4 Architecture Principles

  2. B

    1 Statement of Architecture Work - 2 Architecture Principles - 3 Architecture Requirements Specification - 4 Request for Architecture Work

  3. C

    1 Architecture Principles - 2 Architecture Requirements Specification - 3 Request for Architecture Work- 4 Statement of Architecture Work

  4. D

    1 Request for Architecture Work - 2 Statement of Architecture Work - 3 Architecture Principles - 4 Architecture Requirements Specification

Show answer and explanation

Correct answer: D

Explanation

The Request for Architecture Work is a deliverable that is sent from the sponsor and triggers the start of an architecture development cycle. It defines the scope, budget, schedule, and deliverables for a specific architecture project. The Statement of Architecture Work is a deliverable that is produced by the architect and defines the approach and resources needed to complete an architecture project. It forms the basis of a contractual agreement between the sponsor and the architecture organization. The Architecture Principles are a deliverable that is produced by the architect and defines the general rules and guidelines for the architecture work. They reflect the business principles, business goals, and business drivers of the organization. The Architecture Requirements Specification is a deliverable that is produced by the architect and defines the requirements that govern the architecture work. It covers both functional and non-functional requirements as well as constraints and assumptions.

Question 3 Single choice

Which of the following does the TOGAF standard describe as a package of functionality defined to meet business needs across an organization?

  1. A

    An application

  2. B

    A solution architecture

  3. C

    A building block

  4. D

    A deliverable

Show answer and explanation

Correct answer: C

Explanation

https://pubs.opengroup.org/architecture/togaf8-doc/arch/chap32.html

Question 4 Single choice

Please read this scenario prior to answering the question.
You are employed as an Enterprise Architect at a healthcare company. The company operates over 250 hospitals and is dedicated to transforming healthcare with new ideas and advancements. The company has multiple divisions including surgery centers, freestanding emergency departments, urgent care clinics, and physician practices. They also develop and supply a range of products and services, many with specialized systems and clinical needs.

The company's Enterprise Architecture (EA) department has been operating for several years and has mature, well-developed architecture governance and development processes following the TOGAF standard. The Chief Information Officer (CIO) is the sponsor of the Enterprise Architecture program. Healthcare is a highly controlled sector, and the company must maintain robust security practices to keep patient information private and prevent data breaches. The company shares electronic health records with multiple providers and has standardized its medical coding for billing and reporting.

Many of the company's rivals have begun using Artificial Intelligence (AI) in their operations, and the indications are that this will be transformative for healthcare delivery. This is something the EA department has been interested in for a while, and they had recently submitted an Architecture Change Request which was approved. As a result, the CIO has approved a Request for Architecture Work to implement AI-based solutions in the company.

The project has been established and you have been assigned to work on it. Stakeholders, concerns, and business requirements have been identified. The stakeholders have made it clear that timely implementation of changes can be life-critical, and that changes should be focused on improving patient outcomes. They also have a concern about disruption due to the changes and require the systems to preserve clinical data access and maintain critical life-support systems during any outages.

The scope of what is inside and what is outside the architecture efforts has now been confirmed. Your task is to revisit and review the Architecture Principles, as they form part of the constraints on architecture work.

Question:
The EA team leader has asked you to explain which Architecture Principles are most relevant for this project.

Based on the TOGAF standard, which of the following is the best answer? (Note: You should assume the company follows the example set of Architecture Principles that are provided in the TOGAF standard, ADM Techniques, Architecture Principles chapter.)

  1. A

    Compliance with the Law is critical for a company operating in one of the most heavily regulated industries. This principle provides the foundation for ensuring the initiative meets all legal requirements for patient data handling. Interoperability ensuring systems can exchange and use information is important for cross-provider data sharing. Control Technical Diversity will be vital for standardizing the AI implementations across multiple divisions that share electronic health records with standardized medical coding.

  2. B

    Responsive Change Management emphasizes implementing changes in a timely manner to meet user needs and limiting downtime during change. Primacy of Principles makes it clear that the set of principles applies equally to all divisions and clinical departments. This will ensure that the regulatory requirements across the company are met. Maximize Benefit to the Enterprise will ensure that decisions are made to provide maximum benefit to the company.

  3. C

    Common Use Applications promotes standardization across divisions for the solutions, aligning with the company's existing practice of standardized medical coding. Information Management is Everybody ' s Business is relevant because clinical staff, administrative personnel, and IT teams all need to collaborate on information management decisions. Data is Accessible is highly relevant to the healthcare industry. This is needed for users to perform their functions and leads to efficiency and effectiveness.

  4. D

    Common Vocabulary and Data Definitions is essential for standardized medical coding and cross-provider data sharing. This ensures the solutions will properly interpret clinical data consistently across divisions. Data Security is critical to protect patient information aligned with the regulations. It ensures data integrity and system availability for critical care. Requirements-Based Change ensures changes respond to business and clinical needs, supporting changes being driven by clinical requirements.

Show answer and explanation

Correct answer: D

Explanation

Option D most precisely reflects the TOGAF example Architecture Principles and aligns directly with the explicit constraints described in the scenario.

The healthcare environment described is highly regulated, data-sensitive, and operationally life-critical. The principle Common Vocabulary and Data Definitions is fundamental because the organization shares electronic health records across providers and relies on standardized medical coding. For AI-based systems to function correctly and safely, consistent interpretation of clinical data across divisions is mandatory.

The principle Data Security directly addresses the requirements for privacy, prevention of breaches, regulatory compliance, integrity of patient records, and continuous availability of systems that support life-critical operations. In healthcare, availability is not merely operational-it is safety-related.

The principle Requirements-Based Change ensures that architecture decisions are driven by validated business and clinical requirements. The scenario clearly emphasizes patient outcomes, life-critical timing, and minimal disruption. This principle ensures AI adoption is justified by measurable clinical and business needs rather than by competitive pressure alone.

The other options contain partially relevant principles but do not collectively address clinical data consistency, regulatory protection, safety, and requirement traceability as comprehensively as Option D.

Therefore, according to TOGAF Architecture Principles guidance, Option D is the best answer.

Question 5 Single choice

Consider the following statement:

Separate projects may operate their own ADM cycles concurrently, with relationships between the different projects

What does it illustrate?

  1. A

    Implementation governance

  2. B

    Enterprise Architecture

  3. C

    Iteration

  4. D

    Requirements management

Show answer and explanation

Correct answer: C

Explanation

The statement illustrates iteration and the ADM. Iteration is the technique of repeating a process or a phase with the aim of improving or refining the outcome. Iteration allows for feedback loops and adaptations at any point in the architecture development and transition process. Separate projects may operate their own ADM cycles concurrently, with relationships between the different projects, to address different aspects or levels of the architecture in an iterative manner.
References:
The TOGAF Standard |
The Open Group Website, Section 3.1 Introduction to the ADM.

Question 6 Single choice

In which section of the TOGAF template for Architecture Principles would a reader find the answer to the question of "

How does this affect me"?

  1. A

    Implications

  2. B

    Name

  3. C

    Rationale

  4. D

    Statement

Show answer and explanation

Correct answer: A

Explanation

https://pubs.opengroup.org/pocket-guides/togaf-pocket-guide/main/chap07.html

Implications:

Should highlight the requirements, both for the business and IT, for carrying out the principle - in terms of resources, costs, and activities/tasks. It will often be apparent that current systems, standards, or practices would be incongruent with the principle upon adoption. The impact on the business and the consequences of adopting a principle should be clearly stated. The reader should readily discern the answer to: "How does this affect me?". It is important not to oversimplify, trivialize, or judge the merit of the impact. Some of the implications will be identified as potential impacts only, and may be speculative rather than fully analyzed.

Question 7 Single choice

Which of the following describes the practice by which the enterprise architecture is managed and controlled at an enterprise-wide level?

  1. A

    Corporate governance

  2. B

    Architecture governance

  3. C

    IT governance

  4. D

    Technology governance

Show answer and explanation

Correct answer: B

Explanation

According to the TOGAF Standard, 10th Edition, architecture governance is "the practice by which enterprise architectures and other architectures are managed and controlled at an enterprise-wide level" 1.
Architecture governance ensures that the architecture development and implementation are aligned with the strategic objectives, principles, standards, and requirements of the enterprise, and that they deliver the expected value and outcomes. Architecture governance also involves establishing and maintaining the architecture framework, repository, board, contracts, and compliance reviews 1. The other options are not correct, as they are not the term used by the TOGAF Standard to describe the practice by which the enterprise architecture is managed and controlled at an enterprise-wide level. Corporate governance is "the system by which an organization is directed and controlled" 2, and it covers aspects such as leadership, strategy, performance, accountability, and ethics. IT governance is "the system by which the current and future use of IT is directed and controlled" 2, and it covers aspects such as IT strategy, policies, standards, and services. Technology governance is "the system by which the technology decisions and investments are directed and controlled" 3, and it covers aspects such as technology selection, acquisition, deployment, and maintenance.
References:
1: TOGAF Standard, 10th Edition, Part VI: Architecture Governance, Chapter
44: Introduction.
2: TOGAF Standard, 10th Edition, Part I: Introduction, Chapter 3:
3: TOGAF Series Guide: Using the TOGAF Framework to Define and Govern Service-Oriented Architectures, Part II: Using the TOGAF Framework to Define and Govern Service-Oriented Architectures, Chapter
5: Technology Governance.

Question 8 Single choice

Please read this scenario prior to answering the question
You are employed as an Enterprise Architect at a technology company, reporting directly to the Chief Enterprise Architect. The company supplies personnel and delivers cloud-based solutions to numerous government agencies.
The nature of the business is such that the data and the information stored on the company systems is the company ' s major asset and is highly confidential. The company employees work remotely and need constant access to the company systems, which is done by the public infrastructure. They use message encryption, secure internet connections using Virtual Private Networks (VPNs), and other standard security measures. The company provides computer security awareness training for all its staff.
The Chief Security Officer (CSO) has noted an increase in distributed denial of service (DDoS) attacks on companies with a similar profile. The CSO understands that even with thorough preparation, a major attack could stop employees from being able to do their jobs. This could lead to a large financial loss, damage to the company ' s reputation with customers, and employees being unable to work.
A risk assessment has been completed and the company has looked for cyber insurance that covers such attacks. The price for this insurance is very high. The CTO has decided not to get cyber insurance to cover such attacks.
The company follows the TOGAF standard as the method and guiding framework for its Enterprise Architecture (EA) practice. The Chief Technology Officer (CTO) is the sponsor

of the activity. The practice uses an iterative approach for its architecture development.
This has enabled the decision makers to gain valuable insights into the different aspects of the business Please read this scenario prior to answering the question
You have been asked to describe the steps you would take to strengthen the current architecture to improve data protection.
Based on the TOGAF standard which of the following is the best answer?

  1. A

    You would request technology updates from existing suppliers that improve thecompany ' s capabilities to detect, react, and recover from an incident. Youwould run a simulated ransomware attack to evaluate the current EnterpriseArchitecture ' s resilience and recovery capabilities. Using the findings, youwould perform a gap analysis of the current Enterprise Architecture, andprepare change requests to address identified gaps. You would document thechanges implemented and add to the Architecture Repository.

  2. B

    You would run a planning exercise to assess the business continuityrequirements and analyze the current Enterprise Architecture for gaps. Youcreate a formal change request related to business resilience and maintainingcritical business functions. You would arrange a meeting of the ArchitectureBoard to assess and approve the change request. Once approved you wouldcreate a new Request for Architecture Work to begin an ADM cycle toimplement the changes.

  3. C

    You would ensure that business value and cost of continuity measures areunderstood by key stakeholders, and that the company has in place up-to-dateprocesses for managing change to the current Enterprise Architecture. Yourecommend that DDoS mitigation be addressed at the infrastructure level toensure effective, scalable protection. Changes should be made to the baselinedescription of the Technology Architecture. The changes should be approvedby the Architecture Board and implemented by change managementtechniques.

  4. D

    You would hold an Architecture Compliance Review with the scope to examinethe company ' s ability to respond to such attacks. You would identify thedepartments involved and have them nominate representatives. You wouldthen tailor checklists to address the requirement for increased businesscontinuity and resilience. You would circulate the checklists to the nominatedrepresentatives for them to complete. You would review the completedchecklists, identifying and resolving issues. You would then determine andpresent your recommendations to the Architecture Board.

Show answer and explanation

Correct answer: B

Explanation

In this scenario, the CTO has not purchased cyber-insurance, the CSO is concerned about increased DDoS risk, and YOU (the EA) are asked "to describe the steps you would take to strengthen the current architecture to improve data protection." Because the company follows the TOGAF standard and uses an iterative ADM cycle, the correct response must:

Start with the risk/continuity concern
Use the formal TOGAF change management process Lead to a Request for Architecture Work

Initiate a new ADM cycle to update the architecture properly Ensure Architecture Board governance Option B is the only answer that matches TOGAF's required process.
# Why Option B is correct (TOGAF-aligned)
Option B follows TOGAF's Architecture Change Management (Phase H) process:
Assess the business continuity requirements-Correct: Phase H requires evaluating change triggers such as new risks, threats, or incidents.- DDoS risk # business continuity concern # legitimate architecture change trigger.

Analyze the current architecture for gaps-Correct: TOGAF Phase H requires assessing whether the current baseline architecture can support required resilience.

Create a formal Change Request-Exactly correct: Phase H outputs Architecture Change Requests (ACRs) for significant changes.- ACR includes description, rationale, and impact (in this case: resilience, continuity, and data protection).

Architecture Board reviews/approves the change request-Correct: All major architecture changes must go through Architecture Governance.

Create a new Request for Architecture Work (RFAW)- Required when the change is significant and needs a new ADM cycle.- Strengthening data protection and business continuity DEFINITELY qualifies as a major change.

Begin a new ADM cycle to implement the changes-Perfectly aligned with TOGAF's iterative approach: Business continuity # update Technology Architecture # updated security patterns # updated Target Architecture.

This is exactly the TOGAF-prescribed method to strengthen an architecture when significant new risks appear.

Therefore, Option B is the correct and TOGAF-compliant answer.
# Why the other options are incorrect
A - Not TOGAF-aligned Starts with vendors and simulations (not TOGAF-first steps). No mention of Architecture Board or Change Management.

No Request for Architecture Work.
Gap analysis alone is not the first step for significant architectural risk.
C - Too narrow and skips TOGAF governance Jumps straight to modifying the Technology Architecture baseline.
No Change Request, no RFAW, no ADM cycle initiation.
Recommends a solution ("DDoS mitigation at infrastructure level") before architectural assessment.
D - Misuses Architecture Compliance Review
Architecture Compliance Reviews check conformity to an existing architecture-not evaluate new risks or design resilience enhancements.

A compliance review is not the correct first step for addressing new threats.

Question 9 Single choice

Which of the following describes the concept of an Enterprise Architecture Capability?

  1. A

    The ability to distinguish between different types of architectural assets that exist at different levels of abstraction in the enterprise.

  2. B

    The ability to follow general rules and guidelines that relate to Enterprise Architecture work and that enable decision-making.

  3. C

    The ability to strike a balance between positive and negative outcomes resulting from the realization of opportunities.

  4. D

    The ability to develop, use and sustain the architecture of a particular enterprise using architecture to govern change.

Show answer and explanation

Correct answer: D

Explanation

An Enterprise Architecture Capability is the organizational ability to develop, maintain, govern, and sustain Enterprise Architecture as an ongoing business capability. It includes governance structures, roles, responsibilities, processes, methods, skills, tools, repositories, and supporting resources necessary to enable architecture-driven change across the enterprise.

TOGAF explains that an Architecture Capability allows an organization to use architecture effectively to govern transformation and support strategic business objectives. It is much broader than simply maintaining architecture artifacts or following principles.

Option A describes the Enterprise Continuum.
Option B relates to Architecture Principles.
Option C describes risk management concepts.

Therefore, the correct answer is .D

Question 10 Single choice

Consider the following ADM phases objectives.

Which phase does each objective match?

  1. A

    1F-2G-3G-4H

  2. B

    1H-2F-3F-4G

  3. C

    1F-2G-3H-4H

  4. D

    1G-2H-3H-4F

Show answer and explanation

Correct answer: A

Explanation

1F: To define an Implementation and Migration Strategy that will achieve an orderly transition from the Baseline to Target Architectures 2G: To perform appropriate governance functions while the solution is being implemented 3G: To ensure conformance with the Target Architecture by implementation projects 4H: To establish procedures for continual monitoring and assessment of the performance of the solution in operation Reference: The TOGAF Standard | The Open Group Website, Section 3.2 ADM Phases.