
Reliable OGEA-102 Dumps Questions Available as Web-Based Practice Test Engine
Correct and Up-to-date The Open Group OGEA-102 BrainDumps
NEW QUESTION # 16
Scenario
You are working as an Enterprise Architect within a large manufacturing company. The company has multiple divisions located worldwide.
After a recent study, senior management is concerned about the impact of the company's multiple data centers and duplication of applications on business efficiency. To address this concern, a strategic architecture has been defined; it will help improve the ability to meet customer demand and improve the efficiency of operations. The strategic architecture involves the consolidation of multiple application programs that are currently used in different divisions and putting them all onto a cloud-based solution instead.
Each division has completed the Architecture Definition documentation to meet its own specific operational requirements. The enterprise architects have analyzed the corporate changes and implementation constraints. A consolidated gap analysis has been completed. Based on its results, the architects have reviewed the requirements, dependencies, and interoperability requirements needed to integrate the cloud-based solution. The architects have completed the Business Transformation Readiness Assessment. Based on all these factors, they have produced a risk assessment. They have also completed the draft Implementation and Migration Plan, the draft Architecture Roadmap, and the Capability Assessment deliverables.
Due to the risks of changing from the current environment, the decision has been taken that a gradual approach is needed to implement the target architecture. It will likely take a few years to complete the whole implementation process.
The company has a mature Enterprise Architecture (EA) practice and uses the TOGAF standard for its architecture development method. The EA practice is engaged throughout all the divisions, with implementation governance assigned to a business line. In addition to providing guidance on using architecture frameworks, including business planning, project/portfolio management, and operations management, the EA program is sponsored by the Chief Information Officer (CIO).
You have been asked to decide on the next steps for the migration planning.
Based on the TOGAF standard, which of the following is the best answer?
- A. You conduct a series of Compliance Assessments to ensure that the architecture is being implemented according to the contract. The Compliance Assessment verifies that the implementation team is using the proper development methodology. It should include deployment of monitoring tools and ensure that performance targets are being met. If they are not met, then you would identify changes to performance requirements and update those in the Implementation and Migration Plan.
- B. You examine how the Implementation and Migration Plan affects the other frameworks being used in the organization. You coordinate the planning with the business planning, project/portfolio management, and operations management frameworks. You assign a business value to each project, considering the available resources and how well they align with the strategy. You then update the architecture roadmap and the Implementation and Migration Plan.
- C. You update the Architecture Definition Document, which includes setting project objectives and documenting the final requirements. This will ensure that the architecture remains relevant and responsive to the needs of the enterprise. You then produce an Implementation Governance Model to manage the lessons learned prior to finalizing the Implementation and Migration Plan. You recommend that lessons learned be applied as changes to the architecture without review.
- D. You assess the business value for each project by applying the Business Value Assessment Technique. The assessment should focus on return on investment and performance evaluation criteria to prioritize the most progress of the architecture transformation. You confirm and plan a series of Transition Architecture phases using an Architecture Definition Increments Table. You document the lessons learned and generate the final Implementation and Migration Plan.
Answer: B
Explanation:
Context of the Scenario
The organization is currently in the Migration Planning phase, which corresponds to Phase F of the TOGAF ADM (Architecture Development Method). The key activities for this phase involve:
Evaluating dependencies and impacts on other organizational frameworks.
Aligning the roadmap and migration plan with strategic objectives and available resources.
Addressing the risks of transitioning from the current architecture to the target architecture using a phased approach.
The deliverables (Architecture Roadmap, Capability Assessment, etc.) and assessments (Gap Analysis, Risk Assessment, Transformation Readiness) have already been developed. The next step is to refine and finalize the migration planning.
Option Analysis
Option A:
While updating the Architecture Definition Document could ensure alignment, this step was completed in earlier phases (B, C, D). At this stage, further changes to the architecture must go through a formal governance review, and applying lessons learned without review contradicts TOGAF principles.
Producing an Implementation Governance Model is more relevant in Phase G (Implementation Governance), not in Phase F.
Conclusion: Incorrect, as it suggests revisiting earlier steps and does not align with the current phase.
Option B:
Conducting Compliance Assessments ensures the architecture is implemented correctly, but this is a task for Phase G (Implementation Governance) after migration planning has been finalized and implementation begins.
Deployment of monitoring tools is also part of implementation and governance activities, not migration planning.
Conclusion: Incorrect, as it focuses on tasks belonging to a later phase.
Option C:
Examining how the Implementation and Migration Plan affects other organizational frameworks is critical in Phase F, as TOGAF emphasizes alignment with business planning, project/portfolio management, and operations management.
Assigning business value to each project ensures prioritization and optimal allocation of resources.
Updating the Architecture Roadmap and the Implementation and Migration Plan based on this analysis ensures strategic alignment and readiness for implementation.
Conclusion: Correct, as it addresses the key objectives of the Migration Planning phase comprehensively.
Option D:
Applying the Business Value Assessment Technique is valid for prioritizing initiatives but is a limited aspect of Migration Planning.
Planning Transition Architecture phases and documenting lessons learned are valid, but this does not address broader organizational impacts or dependencies as effectively as Option C.
Conclusion: Narrow focus; less comprehensive than Option C.
Reference to TOGAF
Phase F (Migration Planning): The focus is on aligning the migration plan with business objectives, considering organizational dependencies, and prioritizing projects (TOGAF 9.2, Chapter 12).
Architecture Roadmap and Implementation Plan: Updated to reflect changes in priorities and alignment with business frameworks (TOGAF 9.2, Section 12.4).
Framework Integration: Collaboration with other frameworks (e.g., business planning, portfolio management) ensures alignment across the organization (TOGAF 9.2, Section 6.5.2).
Business Value Assessment Technique: Used to prioritize initiatives based on return on investment and performance criteria (TOGAF 9.2, Section 24.4).
NEW QUESTION # 17
Please read this scenario prior to answering the question
You are employed as an Enterprise Architect within a multinational company. The company has been very successful and has been buying companies around the world. This has led to a growing number of manufacturing divisions in various locations with a complex supply chain.
The top management recently expressed concerns about the company's effectiveness because of its multiple data centers and duplicate applications. The EA team has been working on a project to solve this issue. An analysis shows that supply chain issues have led to not enough products being produced to meet all the customer demand.
A strategic architecture has been defined to help meet customer demand and manage the supply chain more effectively. The strategic architecture involves combining different Enterprise Resource Planning (ERP) applications that are currently used separately in the company's production sites.
Each division has finished the Architecture Definition documentation to address their own specific manufacturing needs. The Enterprise Architects have agreed an overall strategy for the migration. They have defined a set of work packages that address the gaps found. They have defined the intermediate architectural states between the Baseline and Target architecture to add a new ERP environment into the company.
Because of the risks posed by this change from the current environment, the architects have recommended that a phased approach should be taken to implement the target architecture with several stages of change. They have created a draft roadmap with the implementation process estimated to take over two years.
The company has an established Enterprise Architecture (EA) practice and follows the TOGAF Architecture Development Method. The company also uses various management frameworks such as business planning, project/portfolio management, and operations management. The EA program is sponsored by the Chief Information Officer (CIO). In your role as an Enterprise Architect within the EA team, you work closely with the important stakeholders from the various divisions within the company.
Refer to the scenario
You have been assigned to plan the next steps for the migration. Which approach will you choose?
Based on the TOGAF standard which of the following is the best answer?
- A. You conduct a series of Compliance Assessments to check that the architecture is being implemented as required by the contract. This is done now to confirm that the implementation team is following the correct development process, and if not, so course correction is viable. This involves using monitoring tools and making sure that performance targets are being achieved. If the targets are not met, you would then need to make adjustments to the performance requirements and update them in the Implementation and
- B. You finalize the Architecture Definition documentation with updates to reflect the implementation approach. You ensure that Implementation and Migration Plan is consistent with the chosen approach. You identify the resources needed to undertake the development projects. You would then produce an Implementation Governance Model to manage the lessons learned before finishing the plan. You ensure that the lessons learned are applied to the Implementation and Migration Plan.
- C. You estimate the business value for each project by applying the Business Value Assessment Technique to prioritize the migration projects and project steps. The assessment should focus on return on investment and criteria for evaluating performance to track the progress of the architecture transformation. You would confirm and plan a series of Transition Architecture phases using a table of Architecture Definition Increments that lists the projects. You then update the Implementation and Migration Plan.
- D. You will focus on project selection. You make sure that the Implementation and Migration plan aligns with the other management frameworks in use in the company. Next, you assign a value to each work package, taking into account the resources available and how they fit into the overall strategy. Using these work packages, you estimate resource requirements and timings. You then select which projects will be included in the Implementation and Migration Plan.
Answer: C
Explanation:
Migration Plan.
Explanation:
At this stage in the scenario:
A strategic architecture has been completed.
All divisions have completed their Architecture Definition Documents.
Work packages have been defined.
Transition Architectures between Baseline and Target are already identified.
A draft roadmap exists for a multi-year phased migration.
You are now asked to plan the next steps for the migration, which aligns exactly with TOGAF ADM Phase F: Implementation and Migration Planning.
In Phase F, TOGAF prescribes the following key activities:
Evaluate and prioritize projects and work packages
Determine business value, cost, risk, dependencies
Confirm Transition Architectures and sequencing
Update and finalize the Implementation & Migration Plan
Option B is the ONLY answer that correctly follows these required TOGAF steps.
✔ Why Option B is correct
Option B states:
"Estimate the business value for each project by applying the Business Value Assessment Technique ... to prioritize the migration projects."
✔ This is a TOGAF-recommended technique specifically for Phase F to evaluate and prioritize transformations using value, risk, and ROI.
"Confirm and plan a series of Transition Architecture phases ... using a table of Architecture Definition Increments."
✔ Exactly aligned with TOGAF:
Transition Architectures were identified earlier.
In Phase F, they must be confirmed, sequenced, and documented.
"Update the Implementation and Migration Plan."
✔ This is the required output of ADM Phase F.
✔ At this point, the plan must be validated and finalized based on value and prioritization.
Thus, Option B directly matches TOGAF's prescribed migration planning process.
✘ Why the other options are incorrect
A - Incorrect
Suggests finalizing Architecture Definition documentation-this was already completed by each division.
Introduces an "Implementation Governance Model," which is not a TOGAF artifact at this stage.
Focuses on lessons learned BEFORE execution, which is not appropriate for migration planning.
C - Incorrect
Focuses only on project selection and resource assignment.
Does not use TOGAF techniques for value/risk evaluation.
Does not reference Transition Architectures, which are central in the scenario.
Oversimplifies Implementation & Migration Planning to resource scheduling.
D - Incorrect
Compliance Assessments occur DURING execution, not before migration planning.
At this stage, no implementation has started, so compliance reviews are premature.
Adjusting performance requirements now has no alignment with TOGAF's ADM sequence.
NEW QUESTION # 18
Scenario:
You are working as an Enterprise Architect within a company providing legal services. The company operates in many countries and has a complicated structure. Every office must follow the local regulations in their country.
The company's Enterprise Architecture (EA) department has been operating for several years and has mature, well-developed architecture governance and development processes based on the TOGAF standard. In addition to the EA program, the company has several management frameworks, including business planning, project/portfolio management, and operations management. The Architecture Board includes representatives from all parts of the company.
The Chief Information Officer (CIO) is the sponsor of the Enterprise Architecture program. The CIO has actively encouraged architecting with agility within the EA department as the preferred approach for projects. The CIO has given approval for a Request for Architecture Work to explore the adoption of an AI-powered system for managing legal cases and financial processes.
Senior management has become more concerned about business performance, especially with the advancements in Artificial Intelligence (AI). Many of the company's competitors have started using AI to assist with legal strategies, streamline processes, and boost productivity. One of the most important benefits AI has for the business is its ability to increase accuracy and minimize mistakes.
Some of the top managers are worried about a change in the way of working, and if it will achieve the business goals. Their staff also fear that management will use the AI system to measure their performance. The CIO wants to know how to address these concerns and reduce risks.
The new system is expected to guide legal professionals and analysts on which tasks to focus on. The main goals are to improve productivity and make better use of staff. In addition, the CIO hopes these changes will lead to higher customer satisfaction.
Refer to the scenario:
You have been asked to respond to the Chief Information Officer (CIO) recommending an approach that would enable the development of an architecture that addresses the concerns of the top managers and the multiple branches in different parts of the company.
Based on the TOGAF standard, which of the following is the best answer?
- A. You recommend that models be created for each of the Business, Application, and Technology architectures. These can be used to ensure that the system will be compliant with the local regulations for each operating entity. This ensures that all necessary data and detail is addressed. A formal review should be held with the stakeholders to verify that their concerns have been properly addressed by the models.
- B. You recommend creation of a set of business models that can be applied uniformly across all AI-related architecture projects. These should be developed in a portable format to ensure maximum portability across the many tools used in the firm. Each architecture should then be defined based on this fixed set of models. All concerned stakeholders can then examine the models to ensure that their needs have been addressed.
- C. You recommend that an analysis of the stakeholders is undertaken. This will allow the architects to define groups of partners (the stakeholders) who have common concerns and include development of a Stakeholder Map. The concerns and relevant views should then be defined for each group and recorded in the Architecture Vision document. To reduce risk, you include a requirement that there be progressive development of the target architecture to get regular feedback.
- D. You recommend that a Communications Plan be created to address the key stakeholders, particularly influential partners. This plan should include a report summarizing the key features of the architecture with respect to each location and reflect the stakeholders' requirements. You will check with each key stakeholder that their concerns have been addressed. Risk mitigation should be explicitly addressed as a component of the architecture being developed.
Answer: C
Explanation:
The correct answer is B, as it aligns with TOGAF's stakeholder management approach, ensuring that stakeholder concerns are captured and addressed iteratively throughout the architecture development process.
Analysis of the Correct Answer (Option B):
Stakeholder Analysis and Mapping
The scenario highlights that top managers and staff are worried about the changes AI will bring.
TOGAF recommends stakeholder analysis early in the ADM process to ensure that concerns, expectations, and risks are documented.
Creating a Stakeholder Map groups stakeholders by common concerns, allowing architects to develop tailored viewpoints.
Recording Concerns in the Architecture Vision Document
The Architecture Vision (ADM Phase A) serves as a high-level guiding document.
Capturing stakeholder concerns in the Vision document ensures alignment between business goals and technology implementation.
Iterative Development and Regular Feedback
The scenario describes an AI-powered system with major business impacts, so incremental validation is necessary.
TOGAF emphasizes progressive development to manage risk and validate requirements continuously.
Regular feedback loops help mitigate resistance from top managers and staff.
Why Other Options Are Incorrect?
Option A: Creating Models for Business, Application, and Technology Architectures Incorrect because while compliance is important, it does not address stakeholder concerns directly.
The scenario is about ensuring buy-in from top managers and employees, not just regulatory compliance.
Option C: Using Uniform Business Models Across AI Projects
Incorrect because a one-size-fits-all model does not allow for regional and functional differences within the company.
The scenario emphasizes the need to address specific concerns of top managers and different locations, which requires stakeholder-specific customization.
Option D: Creating a Communications Plan
Incorrect because communication alone does not resolve stakeholder concerns.
While communication is useful, the architecture development process should include stakeholder engagement and progressive validation, not just reporting.
Reference:
TOGAF Standard, ADM Phase A - Architecture Vision
TOGAF Standard, Stakeholder Management (ADM Guidelines and Techniques)
TOGAF Enterprise Architecture Principles - The Open Group
NEW QUESTION # 19
Please read this scenario prior to answering the question
Your role is that of a consultant to the Lead Enterprise Architect to an international supplier of engineering services and automated manufacturing systems. It has three manufacturing plants where it assembles both standard and customized products for industrial production automation. Each of these plants has been operating its own planning and production scheduling systems, as well as applications and control systems that drive the automated production line.
The Enterprise Architecture department has been operating for several years and has mature, well-developed architecture governance and development processes that are based on the TOGAF Standard. The CIO sponsors the Enterprise Architecture.
During a recent management meeting, a senior Vice-President highlighted an interview where a competitor company's CIO is reported as saying that their production efficiency had been improved by replacing multiple planning and scheduling systems with a common Enterprise Resource Planning (ERP) system located in a central data center. Some discussion followed, with the CIO responding that the situations are not comparable, and the current architecture is already optimized.
In response, the Architecture Board approved a Request for Architecture Work covering the investigations to determine if such an architecture transformation would lead to improvements in efficiency. You have been assigned to support the architecture team working on this project.
A well-known concern of the plant managers is about the security and reliability of driving their planning and production scheduling from a remote centralized system. Any chosen system would also need to support the current supply chain network consisting of local partners at each of the plants.
Refer to the scenario
You have been asked to explain how you will initiate the architecture project.
Based on the TOGAF Standard, which of the following is the best answer?
- A. You would hold a series of interviews at each of the manufacturing plants using the business scenarios technique. This will allow you to understand the systems and integrations with local partners. You would use stakeholder analysis to identify key players in the engagement, and to understand their concerns. You will then identify and document the key high-level stakeholder requirements for the architecture. You will then generate high level definitions of the baseline and target architectures.
- B. You would research vendor literature and conduct a series of briefings with vendors that are on the current approved supplier list. Based on the findings from the research, you would define a preliminary Architecture Vision including summary views, high-level requirements, and high-level definitions of the baseline and target environments from a business, information systems, and technology perspective. You would then use that to build consensus among the key stakeholders.
- C. You would conduct a pilot project that will enable vendors to demonstrate potential off-the-shelf solutions that address the concerns of the stakeholders. Running a pilot project will save time and money later in the process. Based on the findings of that pilot project, a complete set of requirements can then be developed that will drive the evolution of the architecture. Once the requirements are completed, a formal stakeholder review should be held, and permission sought to proceed to develop the target architecture.
- D. You would develop baseline and target Architectures for each of the manufacturing plants, ensuring that the views corresponding to selected viewpoints address key concerns of the stakeholders. A business case, together with performance metrics and measures should be defined to ensure the architecture meets the business needs. A consolidated gap analysis between the architectures will then validate the approach and determine the capability increments needed to achieve the target state.
Answer: A
Explanation:
The best answer is C. You would hold a series of interviews at each of the manufacturing plants using the business scenarios technique. This will allow you to understand the systems and integrations with local partners. You would use stakeholder analysis to identify key players in the engagement, and to understand their concerns. You will then identify and document the key high-level stakeholder requirements for the architecture. You will then generate high level definitions of the baseline and target architectures.
This answer is based on the TOGAF standard, which recommends the following steps to initiate the architecture project1:
Establish the architecture project
Identify stakeholders, concerns, and business requirements
Confirm and elaborate business goals, business drivers, and constraints Evaluate business capabilities Assess readiness for business transformation Define scope Confirm and elaborate Architecture Principles, including business principles Develop Architecture Vision Define the Target Architecture value propositions and KPIs Identify the business transformation risks and mitigation activities Secure stakeholder and sponsor approval The answer C covers most of these steps, by using the business scenarios technique to elicit and validate the business requirements, goals, drivers, and constraints, as well as the current and future states of the architecture2. The answer C also uses stakeholder analysis to identify and engage the key stakeholders, and to address their concerns and expectations3. The answer C also generates high level definitions of the baseline and target architectures, which can be used to develop the Architecture Vision and the value propositions4.
The other answers are not the best approach for architecture development, because:
Answer A focuses on researching vendor literature and conducting briefings with vendors, which is not the best way to understand the business needs and the current situation of the enterprise. Answer A also defines a preliminary Architecture Vision without involving the stakeholders or validating the requirements, which may lead to misalignment and lack of consensus.
Answer B conducts a pilot project that will enable vendors to demonstrate potential solutions, which is premature and costly at this stage of the architecture project. Answer B also does not address the stakeholder concerns or the current systems and integrations, which may result in gaps and risks. Answer B also develops the requirements after the pilot project, which may not reflect the actual business needs and goals.
Answer D develops baseline and target architectures for each of the manufacturing plants, which may not consider the enterprise-wide perspective and the potential benefits of a common ERP system. Answer D also does not involve the stakeholders or address their concerns, which may result in resistance and conflict. Answer D also does not define the business case or the performance metrics, which are essential for demonstrating the value and feasibility of the architecture.
References: 1: The TOGAF Standard, Version 9.2 - Architecture Vision 2: The TOGAF Standard, Version 9.2 - Business Scenarios 3: [The TOGAF Standard, Version 9.2 - Stakeholder Management] 4: [The TOGAF Standard, Version 9.2 - Architecture Definition Document]
NEW QUESTION # 20
Please read this scenario prior to answering the question
You are the Lead Enterprise Architect at a major agribusiness company. The company's main annual harvest is lentils, a highly valued food grown worldwide. The lentil parasite, broomrape, has been an increasing concern for many years and is now becoming resistant to chemical controls. In addition, changes in climate favor the propagation and growth of the parasite. As a result, the parasite cannot realistically be exterminated, and it has become pandemic, with lentil yields falling globally.
The CEO appreciates the seriousness of the situation and has set out a change in direction that is effectively a new business for the company. There are opportunities for new products, and new markets. The company will use the fields for another harvest and will cease to process third-party lentils. Thus, the target market will change, and the end-products will be different and more varied. This is a major decision and the CEO has stated a desire to repurpose rather than replace so as to manage the risks and limit the costs.
The company has a mature Enterprise Architecture practice based in its headquarters and uses the TOGAF standard as the method and guiding framework. The practice has an established Architecture Capability, and uses iteration for architecture development. The CIO is the sponsor of the activity.
The CIO has assigned the Enterprise Architecture team to this activity. At this stage there is no shared vision, or requirements.
Refer to the scenario
You have been asked to propose the best approach for architecture development to realize the CEO's change in direction for the company.
Based on the TOGAF standard which of the following is the best answer?
- A. You propose that the team focus on architecture definition, with emphasis on defining the change parameters to support this new business strategy that the CEO has identified. Once understood, the team will be in the best position to identify the requirements, drivers, issues, and constraints for the change. You would ensure that the architecture development addresses non-functional requirements to assure that the target architecture is robust and secure.
- B. You propose that the priority is to understand and bring structure to the definition of the change. The team should focus iteration cycles on a baseline first approach to architecture development, and then transition planning. This will identify what needs to change in order to transition from the baseline to the target, and can be used to work out in detail what the shared vision is for the change.
- C. You propose that the team focus its iteration cycles on architecture development by going through the architecture definition phases (B-D) with a baseline first approach.This will support the change in direction as stated by the CEO. It will ensure that the change can be defined in a structured manner and address the requirements needed to realize the change.
- D. You propose that this engagement define the baseline Technology Architecture first in order to assess the current infrastructure capacity and capability for the company. Then the focus should be on transition planning and incremental architecture deployment.
This will identify requirements to ensure that the projects are sequenced in an optimal fashion so as to realize the change.
Answer: B
Explanation:
Based on the TOGAF standard, this answer is the best approach for architecture development to realize the CEO's change in direction for the company. The reason is as follows:
The scenario describes a major business transformation that requires a clear understanding of the current and future states of the enterprise, as well as the gaps and opportunities for change. Therefore, the priority is to understand and bring structure to the definition of the change, rather than focusing on the implementation details or the technology aspects.
The team should use the TOGAF ADM as the method and guiding framework for architecture development, and adapt it to suit the specific needs and context of the enterprise. The team should also leverage the existing Architecture Capability and the Architecture Repository to reuse and integrate relevant architecture assets and resources.
The team should focus iteration cycles on a baseline first approach to architecture development, which means starting with the definition of the Baseline Architecture in each domain (Business, Data, Application, and Technology), and then defining the Target Architecture in each domain. This will help to identify the current and desired states of the enterprise, and to perform a gap analysis to determine what needs to change in order to achieve the business goals and objectives.
The team should then focus on transition planning, which involves identifying and prioritizing the work packages, projects, and activities that will deliver the change. The team should also create an Architecture Roadmap and an Implementation and Migration Plan that will guide the execution and governance of the change.
The team should use the Architecture Vision phase and the Requirements Management phase to work out in detail what the shared vision is for the change, and to capture and validate the stakeholder requirements and expectations. The team should also use the Architecture Governance framework to ensure the quality, consistency, and compliance of the architecture work.
NEW QUESTION # 21
Please read this scenario prior to answering the question
You are working as the Chief Enterprise Architect within a law firm specializing in personal injury cases. Many of the firm's competitors have improved their litigation strategies, and efficiency by streamlining their processes using Artificial Intelligence {Al).
The CIO has approved a Request for Architecture Work to examine the use of Machine Learning in defining a new Al-driven litigation and finance process for the firm. This process would instruct the lawyers and analysts as to what tasks and portfolio they should work on. The key objectives are to increase task profitability, maximize staff utilization, and increase individual profitability.
The CIO has emphasized that the architecture should enable the fast implementation of continuous Machine Learning. The solution will need to be constantly measured for delivered value and be quickly iterated to success.
Some of the partners have expressed concerns about letting the Al make the decisions, others about the risks associated with use of it for the type of service they deliver. The CIO wants to know if these concerns can be addressed, and how risks will be covered by a new architecture enabling Al and Machine Learning.
Refer to the scenario
You have been asked to respond to the CIO recommending an approach that would enable the development of an architecture that addresses the concerns of the CIO and the concerns of the partners.
Based on the TOGAF standard which of the following is the best answer?
- A. You recommend that all possible models be created for each candidate architecture that will enable the Al and Machine Learning solution. This ensures that all the necessary data and detail is addressed. A formal review should be held with the stakeholders to verify that their concerns have been properly addressed by the models. Agility will be considered during Phase G Implementation Governance.
- B. You recommend creation of a set of business models that can be applied uniformly across all architecture projects. The stakeholders will be trained to understand the business models to ensure they can see that their concerns are being addressed. Risk will be addressed once the Security Architecture is developed, which will happen later to avoid slowing down the agility required by the CIO.
- C. You recommend that a Communications Plan be created to address the key stakeholders, the most powerful and influential partners. This plan should include a report that summarizes the key features of the architecture reflecting their requirements. You will check with each key stakeholder that their concerns are being addressed. Risk mitigation and agility will be explicitly addressed as a component of the architecture being developed.
- D. You recommend that an analysis of the stakeholders is undertaken resulting in documenting the stakeholders and their concerns in a Stakeholder Map. The concerns and relevant views should then be defined for each group and recorded in the Architecture Vision document. The requirements will include risk mitigation through regular assessments. This will also allow a supervised agile implementation of the continuous Machine Learning.
Answer: D
Explanation:
A Stakeholder Map is a technique that can be used to identify and classify the stakeholders of the architecture work, and to document their key interests, requirements, and concerns. A stakeholder is any person, group, or organization that has a stake in the outcome of the architecture work, such as the sponsor, the client, the users, the suppliers, the regulators, or the competitors. A Stakeholder Map can help to understand the needs and expectations of the stakeholders, and to communicate and engage with them effectively1 The steps for creating a Stakeholder Map are:
Identify the stakeholders of the architecture work, using various sources and methods, such as interviews, surveys, workshops, or existing documents.
Classify the stakeholders according to their roles, responsibilities, and relationships, using various criteria and dimensions, such as power, influence, interest, attitude, or impact.
Define the concerns and relevant views for each stakeholder group, using various techniques, such as business scenarios, use cases, or value propositions. A concern is a key interest or issue that is relevant to the stakeholder, such as a goal, a problem, a need, or a risk. A view is a representation of the system of interest from the perspective of one or more stakeholders and their concerns.
Record the stakeholders and their concerns in a Stakeholder Map, which shows the mapping between the stakeholder groups, the concerns, and the views. The Stakeholder Map also shows the dependencies, assumptions, and issues related to each stakeholder and concern.
Therefore, the best answer is B, because it recommends the approach that would enable the development of an architecture that addresses the concerns of the CIO and the partners, using the Stakeholder Map technique. The answer covers the following aspects:
An analysis of the stakeholders is undertaken, which involves identifying, classifying, and defining the stakeholders and their concerns.
The stakeholders and their concerns are documented in a Stakeholder Map, which provides a clear and comprehensive picture of the stakeholder landscape and their interests.
The concerns and relevant views are recorded in the Architecture Vision document, which is the output of Phase A: Architecture Vision of the Architecture Development Method (ADM), which is the core process of the TOGAF standard that guides the development and management of the enterprise architecture. The Architecture Vision defines the scope and approach of the architecture work, and establishes the business goals and drivers that motivate the architecture work. The Architecture Vision also involves obtaining the approval and commitment of the sponsors and other key stakeholders, and initiating the Architecture Governance process2 The requirements include risk mitigation through regular assessments, which involves identifying, analyzing, and evaluating the risks that may affect the architecture, and determining the appropriate measures or actions to prevent, reduce, or mitigate the risks. Risk mitigation can also involve monitoring and reviewing the risk situation, and communicating and reporting the risk status and actions3 This approach also allows a supervised agile implementation of the continuous Machine Learning, which involves applying agile principles and practices to the architecture development and implementation, such as iterative and incremental delivery, frequent feedback, collaboration, and adaptation. A supervised agile implementation can help to ensure the quality, value, and alignment of the architecture, and to respond to the changing needs and expectations of the stakeholders.
References: 1: The TOGAF Standard, Version 9.2, Part III: ADM Guidelines and Techniques, Chapter 24: Stakeholder Management 2: The TOGAF Standard, Version 9.2, Part II: Architecture Development Method (ADM), Chapter 18: Phase A: Architecture Vision 3: The TOGAF Standard, Version 9.2, Part III: ADM Guidelines and Techniques, Chapter 32: Risk Management : The TOGAF Standard, Version 9.2, Part III: ADM Guidelines and Techniques, Chapter 29: Applying Iteration to the ADM
NEW QUESTION # 22
Please read this scenario prior to answering the question
You are working as the Chief Enterprise Architect within a law firm specializing in personal injury cases. Many of the firm's competitors have improved their litigation strategies, and efficiency by streamlining their processes using Artificial Intelligence {Al).
The CIO has approved a Request for Architecture Work to examine the use of Machine Learning in defining a new Al-driven litigation and finance process for the firm. This process would instruct the lawyers and analysts as to what tasks and portfolio they should work on. The key objectives are to increase task profitability, maximize staff utilization, and increase individual profitability.
The CIO has emphasized that the architecture should enable the fast implementation of continuous Machine Learning. The solution will need to be constantly measured for delivered value and be quickly iterated to success.
Some of the partners have expressed concerns about letting the Al make the decisions, others about the risks associated with use of it for the type of service they deliver. The CIO wants to know if these concerns can be addressed, and how risks will be covered by a new architecture enabling Al and Machine Learning.
Refer to the scenario
You have been asked to respond to the CIO recommending an approach that would enable the development of an architecture that addresses the concerns of the CIO and the concerns of the partners.
Based on the TOGAF standard which of the following is the best answer?
- A. You recommend that all possible models be created for each candidate architecture that will enable the Al and Machine Learning solution. This ensures that all the necessary data and detail is addressed. A formal review should be held with the stakeholders to verify that their concerns have been properly addressed by the models. Agility will be considered during Phase G Implementation Governance.
- B. You recommend creation of a set of business models that can be applied uniformly across all architecture projects. The stakeholders will be trained to understand the business models to ensure they can see that their concerns are being addressed. Risk will be addressed once the Security Architecture is developed, which will happen later to avoid slowing down the agility required by the CIO.
- C. You recommend that a Communications Plan be created to address the key stakeholders, the most powerful and influential partners. This plan should include a report that summarizes the key features of the architecture reflecting their requirements. You will check with each key stakeholder that their concerns are being addressed. Risk mitigation and agility will be explicitly addressed as a component of the architecture being developed.
- D. You recommend that an analysis of the stakeholders is undertaken resulting in documenting the stakeholders and their concerns in a Stakeholder Map. The concerns and relevant views should then be defined for each group and recorded in the Architecture Vision document. The requirements will include risk mitigation through regular assessments. This will also allow a supervised agile implementation of the continuous Machine Learning.
Answer: D
Explanation:
A Stakeholder Map is a technique that can be used to identify and classify the stakeholders of the architecture work, and to document their key interests, requirements, and concerns. A stakeholder is any person, group, or organization that has a stake in the outcome of the architecture work, such as the sponsor, the client, the users, the suppliers, the regulators, or the competitors. A Stakeholder Map can help to understand the needs and expectations of the stakeholders, and to communicate and engage with them effectively1 The steps for creating a Stakeholder Map are:
Identify the stakeholders of the architecture work, using various sources and methods, such as interviews, surveys, workshops, or existing documents.
Classify the stakeholders according to their roles, responsibilities, and relationships, using various criteria and dimensions, such as power, influence, interest, attitude, or impact.
Define the concerns and relevant views for each stakeholder group, using various techniques, such as business scenarios, use cases, or value propositions. A concern is a key interest or issue that is relevant to the stakeholder, such as a goal, a problem, a need, or a risk. A view is a representation of the system of interest from the perspective of one or more stakeholders and their concerns.
Record the stakeholders and their concerns in a Stakeholder Map, which shows the mapping between the stakeholder groups, the concerns, and the views. The Stakeholder Map also shows the dependencies, assumptions, and issues related to each stakeholder and concern.
Therefore, the best answer is B, because it recommends the approach that would enable the development of an architecture that addresses the concerns of the CIO and the partners, using the Stakeholder Map technique. The answer covers the following aspects:
An analysis of the stakeholders is undertaken, which involves identifying, classifying, and defining the stakeholders and their concerns.
The stakeholders and their concerns are documented in a Stakeholder Map, which provides a clear and comprehensive picture of the stakeholder landscape and their interests.
The concerns and relevant views are recorded in the Architecture Vision document, which is the output of Phase A: Architecture Vision of the Architecture Development Method (ADM), which is the core process of the TOGAF standard that guides the development and management of the enterprise architecture. The Architecture Vision defines the scope and approach of the architecture work, and establishes the business goals and drivers that motivate the architecture work. The Architecture Vision also involves obtaining the approval and commitment of the sponsors and other key stakeholders, and initiating the Architecture Governance process2 The requirements include risk mitigation through regular assessments, which involves identifying, analyzing, and evaluating the risks that may affect the architecture, and determining the appropriate measures or actions to prevent, reduce, or mitigate the risks. Risk mitigation can also involve monitoring and reviewing the risk situation, and communicating and reporting the risk status and actions3 This approach also allows a supervised agile implementation of the continuous Machine Learning, which involves applying agile principles and practices to the architecture development and implementation, such as iterative and incremental delivery, frequent feedback, collaboration, and adaptation. A supervised agile implementation can help to ensure the quality, value, and alignment of the architecture, and to respond to the changing needs and expectations of the stakeholders.
NEW QUESTION # 23
Please read this scenario prior to answering the question
You are serving as the Lead Architect for an Enterprise Architecture team within a leading multinational biotechnology company. The company works in three major industries, including healthcare, crop production, and agriculture. Your team works within the healthcare division.
The healthcare division is developing a new vaccine, and has to demonstrate its effectiveness and safety in a set of clinical trials that satisfy the regulatory requirements of the relevant health authorities. The clinical trials are undertaken by its research laboratories at multiple facilities worldwide. In addition to internal research and development activities, the healthcare division is also involved in publicly funded collaborative research projects with industrial and academic partners.
The Enterprise Architecture team has been engaged in an architecture project to develop a secure system that will allow the healthcare researchers to share information more easily about their clinical trials, and work more collaboratively across the organization and also with its partners. This system will also connect with external partners.
The Enterprise Architecture team uses the TOGAF ADM with extensions required to support healthcare manufacturing practices and laboratory practices. Due to the highly sensitive nature of the information that is managed, special care has been taken to ensure that each architecture domain considers the security and privacy issues that are relevant.
The Vice President for Worldwide Clinical Research is the sponsor of the Enterprise Architecture activity. She has stated that disruptions must be minimized for the clinical trials, and that the rollout must be undertaken incrementally.
Refer to the scenario
You have been asked to recommend the approach to identify the work packages for an incremental rollout meeting the requirements.
Based on the TOGAF standard which of the following is the best answer?
- A. You recommend that a Consolidated Gaps. Solutions and Dependencies Matrix is used as a planning tool for creating work packages. For each gap classify whether the solution is either a new development, purchased solution, or based on an existing product. Group the similar solutions together to define the work packages. Regroup the work packages into a set of Capability Increments to transition to the Target Architecture considering the schedule for clinical trials, and document in an Architecture Definition Increments Table.
- B. You recommend that the Solution Building Blocks from a Consolidated Gaps, Solutions and Dependencies Matrix be grouped into a set of work packages. Using the matrix as a planning tool, regroup the work packages to account for dependencies. Sequence the work packages into the Capability Increments needed to achieve the Target Architecture, so that the implementation team can schedule the rollout one region at a time to minimize disruption. Document the work packages for the Enterprise Architecture using a Transition Architecture State Evolution Table.
- C. You recommend that an Implementation Factor Catalog is drawn up to indicate actions and constraints. A Consolidated Gaps. Solutions and Dependencies Matrix should also be created. For each gap. identify a proposed solution and classify it as new development, purchased solution, or based on an existing product. Group similar activities together to form work packages. Identify dependencies between work packages factoring in the clinical trial schedules. Regroup the work packages into a set of Capability Increments scheduled into a series of Transition Architectures.
- D. You recommend that the set of required Solution Building Blocks be determined by identifying those which need to be developed and which need to be procured. Eliminate any duplicates. Group the remaining Solution Building Blocks together to create the work packages using a CRUD (create, read, update, delete) matrix. Rank the work packages and select the most cost-effective options for inclusion in a series of Transition Architectures. Schedule the roll out of the work packages to be sequential across the geographic regions.
Answer: A
NEW QUESTION # 24
Please read this scenario prior to answering the question
You are working as the Chief Enterprise Architect within a law firm specializing in personal injury cases. Many of the firm's competitors have improved their litigation strategies, and efficiency by streamlining their processes using Artificial Intelligence {Al).
The CIO has approved a Request for Architecture Work to examine the use of Machine Learning in defining a new Al-driven litigation and finance process for the firm. This process would instruct the lawyers and analysts as to what tasks and portfolio they should work on. The key objectives are to increase task profitability, maximize staff utilization, and increase individual profitability.
The CIO has emphasized that the architecture should enable the fast implementation of continuous Machine Learning. The solution will need to be constantly measured for delivered value and be quickly iterated to success.
Some of the partners have expressed concerns about letting the Al make the decisions, others about the risks associated with use of it for the type of service they deliver. The CIO wants to know if these concerns can be addressed, and how risks will be covered by a new architecture enabling Al and Machine Learning.
Refer to the scenario
You have been asked to respond to the CIO recommending an approach that would enable the development of an architecture that addresses the concerns of the CIO and the concerns of the partners.
Based on the TOGAF standard which of the following is the best answer?
- A. You recommend that all possible models be created for each candidate architecture that will enable the Al and Machine Learning solution. This ensures that all the necessary data and detail is addressed. A formal review should be held with the stakeholders to verify that their concerns have been properly addressed by the models. Agility will be considered during Phase G Implementation Governance.
- B. You recommend creation of a set of business models that can be applied uniformly across all architecture projects. The stakeholders will be trained to understand the business models to ensure they can see that their concerns are being addressed. Risk will be addressed once the Security Architecture is developed, which will happen later to avoid slowing down the agility required by the CIO.
- C. You recommend that a Communications Plan be created to address the key stakeholders, the most powerful and influential partners. This plan should include a report that summarizes the key features of the architecture reflecting their requirements. You will check with each key stakeholder that their concerns are being addressed. Risk mitigation and agility will be explicitly addressed as a component of the architecture being developed.
- D. You recommend that an analysis of the stakeholders is undertaken resulting in documenting the stakeholders and their concerns in a Stakeholder Map. The concerns and relevant views should then be defined for each group and recorded in the Architecture Vision document. The requirements will include risk mitigation through regular assessments. This will also allow a supervised agile implementation of the continuous Machine Learning.
Answer: D
NEW QUESTION # 25
You are working as an Enterprise Architect within an Enterprise Architecture (EA) team at a multinational energy company. The company is committed to becoming a net-zero emissions energy business by 2050. To achieve this, the company is focusing on shifting to renewable energy production and adopting eco-friendly practices.
The EA team, which reports to the Chief Technical Officer (CTO), has been tasked with overseeing the transformation to make the company more effective through acquisitions. The company plans to fully integrate these acquisitions, including merging operations and systems.
To address the integration challenges, the EA team leader wants to know how to manage risks and ensure that the company succeeds with the proposed changes. Based on the TOGAF Standard, which of the following is the best answer?
- A. The EA team should develop Business Architecture views that demonstrate how stakeholder concerns are addressed and assess each factor for readiness, urgency, and degree of difficulty.
- B. The EA team should evaluate the company's readiness for change by identifying factors that will impact the transformation. These factors will be used to determine initial risks associated with the initiative.
- C. The EA team should document the risks associated with the transformation in an Implementation Factor Catalog to inform decisions during implementation and deployment.
- D. The EA team should create a Business Scenario to fully describe the business problem that is being addressed by the transformation. Once requirements are identified, they should be evaluated in terms of risks. Any residual risks should be escalated to the Architecture Board.
Answer: D
Explanation:
In TOGAF, creating a Business Scenario is a foundational step in defining and understanding the business problem, especially for complex transformations involving multiple stakeholders and systems, such as in this scenario. This method aligns with Phase A (Architecture Vision) of the TOGAF Architecture Development Method (ADM). Here's why this approach is the most effective:
Understanding Business Requirements:
A Business Scenario provides a structured way to capture and analyze the business requirements, stakeholder concerns, and the contextual elements related to the problem. In this scenario, the company faces challenges in integrating newly acquired companies with existing operations, which includes complex stakeholder concerns across different functional areas. Developing a Business Scenario allows the EA team to break down these complexities into identifiable and manageable parts.
Risk Evaluation and Management:
By using the Business Scenario approach, the EA team can not only define the requirements but also assess associated risks systematically. TOGAF emphasizes the importance of risk management through identifying potential risks, evaluating their impact, and defining strategies for handling these risks. The process includes assessing how risks can be avoided, transferred, or reduced-a necessary step in large-scale transformations to ensure that risks are proactively managed.
Residual Risks and Governance:
Any risks that cannot be fully resolved should be identified as residual risks and escalated to the Architecture Board, which is aligned with TOGAF's governance approach. The Architecture Board's role in TOGAF is to provide oversight and make critical decisions on risks that exceed the control of the EA team. This ensures that unresolved risks are managed at the appropriate level of the organization.
Alignment with TOGAF ADM Phases:
The Business Scenario approach directly aligns with the Preliminary and Architecture Vision phases of the TOGAF ADM, which focuses on establishing a baseline understanding of the business context and the strategic transformation required. The detailed understanding of requirements, stakeholder concerns, and risks identified here will guide the subsequent phases of the ADM, including Business Architecture and Information Systems Architecture.
TOGAF Reference (Section 2.6, ADM Techniques):
TOGAF provides guidelines on the creation of Business Scenarios as part of ADM Techniques, highlighting the importance of defining a business problem comprehensively to ensure successful transformation. This method includes identification of stakeholders, business requirements, and associated risks, which aligns well with the company's need for strategic and systematic integration of new business units.
By utilizing a Business Scenario, the EA team ensures that all aspects of the transformation are well understood, risks are identified early, and residual risks are managed effectively, aligning with the company's strategic objectives and the TOGAF framework's guidance on risk management and stakeholder alignment.
NEW QUESTION # 26
Please read this scenario prior to answering the question
Your role is that of a senior architect, reporting to the Chief Enterprise Architect, at a medium-sized company with 400 employees. The nature of the business is such that the data and the information stored on the company systems is their major asset and is highly confidential.
The company employees travel extensively for work and must communicate over public infrastructure using message encryption, VPNs, and other standard safeguards. The company has invested in cybersecurity awareness training for all its staff. However, it is recognized that even with good education as well as system security, there is a dependency on third-parly suppliers of infrastructure and software.
The company uses the TOGAF standard as the method and guiding framework for its Enterprise Architecture (EA) practice. The CTO is the sponsor of the activity.
The Chief Security Officer (CSO) has noted an increase in ransomware (malicious software used in ransom demands) attacks on companies with a similar profile. The CSO recognizes that no matter how much is spent on education, and support, it is likely just a matter of time before the company suffers a significant attack that could completely lock them out of their information assets.
A risk assessment has been done and the company has sought cyber insurance that includes ransomware coverage. The quotation for this insurance is hugely expensive. The CTO has recently read a survey that stated that one in four organizations paying ransoms were still unable to recover their data, while nearly as many were able to recover the data without paying a ransom. The CTO has concluded that taking out cyber insurance in case they need to pay a ransom is not an option.
Refer to the scenario
You have been asked to describe the steps you would take to improve the resilience of the current architecture?
Based on the TOGAF standard which of the following is the best answer?
- A. You would request an Architecture Compliance Review with the scope to examine the company's resilience to ransomware attacks. You would identify the departments involved and have them nominate representatives. You would then tailor checklists to address the requirement for increased resilience. You would circulate to the nominated representatives for them to complete. You would then review the completed checklists, identifying and resolving issues. You would then determine and present your recommendations.
- B. You would ensure that the company has in place up-to-date processes for managing change to the current Enterprise Architecture. Based on the scope of the concerns raised you recommend that this be managed at the infrastructure level. Changes should be made to the baseline description of the Technology Architecture. The changes should be approved by the Architecture Board and implemented by change management techniques.
- C. You would determine business continuity requirements, and undertake a gap analysis of the current Enterprise Architecture. You would make recommendations for change requirements to address the situation and create a change request. You would manage a meeting of the Architecture Board to assess and approve the change request. Once approved you would produce a new Request for Architecture Work to activate an ADM cycle to carry out a project to define the change.
- D. You would monitor for technology changes from your existing suppliers that could improve resilience. You would prepare and run a disaster recovery planning exercise for a ransomware attack and analyze the performance of the current Enterprise Architecture. Using the findings, you would prepare a gap analysis of the current Enterprise Architecture. You would prepare change requests to address identified gaps. You would add the changes implemented to the Architecture Repository.
Answer: C
Explanation:
Business continuity is the ability of an organization to maintain essential functions during and after a disaster or disruption. Business continuity requirements are the specifications and criteria that define the acceptable level of performance and availability of the business processes and services in the event of a disaster or disruption. A gap analysis is a technique that compares the current state of the architecture with the desired state, and identifies the gaps or differences that need to be addressed. A change request is a formal proposal for an amendment to some product or system, such as the architecture. A Request for Architecture Work is a document that describes the scope, approach, and expected outcomes of an architecture project123 The best answer is A, because it describes the steps that would improve the resilience of the current architecture, which is the ability to withstand and recover from a ransomware attack or any other disruption. The steps are:
Determine the business continuity requirements, which specify the minimum acceptable level of performance and availability of the business processes and services in case of a ransomware attack. This would involve identifying the critical business functions, the recovery time objectives, the recovery point objectives, and the dependencies and resources needed for recovery.
Undertake a gap analysis of the current Enterprise Architecture, which compares the current state of the architecture with the desired state based on the business continuity requirements. This would involve assessing the strengths and weaknesses of the current architecture, the risks and opportunities for improvement, and the gaps or differences that need to be addressed.
Make recommendations for change requirements to address the situation and create a change request. This would involve proposing solutions and alternatives to close the gaps, enhance the resilience, and mitigate the risks of the current architecture. The change request would document the rationale, scope, impact, and benefits of the proposed changes, and seek approval from the relevant stakeholders.
Manage a meeting of the Architecture Board to assess and approve the change request. The Architecture Board is a governance body that oversees the architecture work and ensures compliance with the architecture principles, standards, and goals. The meeting would involve presenting the change request, discussing the pros and cons, resolving any issues or conflicts, and obtaining the approval or rejection of the change request.
Once approved, produce a new Request for Architecture Work to activate an ADM cycle to carry out a project to define the change. The Request for Architecture Work would describe the scope, approach, and expected outcomes of the architecture project that would implement the approved change request. The Request for Architecture Work would initiate a new cycle of the Architecture Development Method (ADM), which is the core process of the TOGAF standard that guides the development and management of the enterprise architecture.
NEW QUESTION # 27
Please read this scenario prior to answering the question
You are serving as the Lead Architect for an Enterprise Architecture team within a leading multinational biotechnology company. The company works in three major industries, including healthcare, crop production, and agriculture. Your team works within the healthcare division.
The healthcare division is developing a new vaccine, and has to demonstrate its effectiveness and safety in a set of clinical trials that satisfy the regulatory requirements of the relevant health authorities. The clinical trials are undertaken by its research laboratories at multiple facilities worldwide. In addition to internal research and development activities, the healthcare division is also involved in publicly funded collaborative research projects with industrial and academic partners.
The Enterprise Architecture team has been engaged in an architecture project to develop a secure system that will allow the healthcare researchers to share information more easily about their clinical trials, and work more collaboratively across the organization and also with its partners. This system will also connect with external partners.
The Enterprise Architecture team uses the TOGAF ADM with extensions required to support healthcare manufacturing practices and laboratory practices. Due to the highly sensitive nature of the information that is managed, special care has been taken to ensure that each architecture domain considers the security and privacy issues that are relevant.
The Vice President for Worldwide Clinical Research is the sponsor of the Enterprise Architecture activity. She has stated that disruptions must be minimized for the clinical trials, and that the rollout must be undertaken incrementally.
Refer to the scenario
You have been asked to recommend the approach to identify the work packages for an incremental rollout meeting the requirements.
Based on the TOGAF standard which of the following is the best answer?
- A. You recommend that a Consolidated Gaps. Solutions and Dependencies Matrix is used as a planning tool for creating work packages. For each gap classify whether the solution is either a new development, purchased solution, or based on an existing product. Group the similar solutions together to define the work packages. Regroup the work packages into a set of Capability Increments to transition to the Target Architecture considering the schedule for clinical trials, and document in an Architecture Definition Increments Table.
- B. You recommend that the Solution Building Blocks from a Consolidated Gaps, Solutions and Dependencies Matrix be grouped into a set of work packages. Using the matrix as a planning tool, regroup the work packages to account for dependencies. Sequence the work packages into the Capability Increments needed to achieve the Target Architecture, so that the implementation team can schedule the rollout one region at a time to minimize disruption. Document the work packages for the Enterprise Architecture using a Transition Architecture State Evolution Table.
- C. You recommend that an Implementation Factor Catalog is drawn up to indicate actions and constraints. A Consolidated Gaps. Solutions and Dependencies Matrix should also be created. For each gap. identify a proposed solution and classify it as new development, purchased solution, or based on an existing product. Group similar activities together to form work packages. Identify dependencies between work packages factoring in the clinical trial schedules. Regroup the work packages into a set of Capability Increments scheduled into a series of Transition Architectures.
- D. You recommend that the set of required Solution Building Blocks be determined by identifying those which need to be developed and which need to be procured. Eliminate any duplicates. Group the remaining Solution Building Blocks together to create the work packages using a CRUD (create, read, update, delete) matrix. Rank the work packages and select the most cost-effective options for inclusion in a series of Transition Architectures. Schedule the roll out of the work packages to be sequential across the geographic regions.
Answer: A
Explanation:
A Consolidated Gaps, Solutions and Dependencies Matrix is a technique that can be used to create work packages for an incremental rollout of the architecture. A work package is a set of actions or tasks that are required to implement a specific part of the architecture. A work package can be associated with one or more Architecture Building Blocks (ABBs) or Solution Building Blocks (SBBs), which are reusable components of business, IT, or architectural capability. A work package can also be associated with one or more Capability Increments, which are defined, discrete portions of the overall capability that deliver business value. A Capability Increment can be realized by one or more Transition Architectures, which are intermediate states of the architecture that enable the transition from the Baseline Architecture to the Target Architecture123 The steps for creating work packages using this technique are:
For each gap between the Baseline Architecture and the Target Architecture, identify a proposed solution and classify it as new development, purchased solution, or based on an existing product. A gap is a difference or deficiency in the current state of the architecture that needs to be addressed by the future state of the architecture. A solution is a way of resolving a gap by implementing one or more ABBs or SBBs.
Group similar solutions together to define the work packages. Similar solutions are those that have common characteristics, such as functionality, technology, vendor, or location.
Identify dependencies between work packages, such as logical, temporal, or resource dependencies. Dependencies indicate the order or priority of the work packages, and the constraints or risks that may affect their implementation.
Regroup the work packages into a set of Capability Increments to transition to the Target Architecture. Capability Increments should be defined based on the business value, effort, and risk associated with each work package, and the schedule and objectives of the clinical trials. Capability Increments should also be aligned with the Architecture Vision and the Architecture Principles.
Document the work packages and the Capability Increments in an Architecture Definition Increments Table, which shows the mapping between the work packages, the ABBs, the SBBs, and the Capability Increments. The table also shows the dependencies, assumptions, and issues related to each work package and Capability Increment.
Therefore, the best answer is B, because it describes the approach to identify the work packages for an incremental rollout meeting the requirements, using the Consolidated Gaps, Solutions and Dependencies Matrix as a planning tool.
References: 1: The TOGAF Standard, Version 9.2, Part III: ADM Guidelines and Techniques, Chapter 30: Gap Analysis 2: The TOGAF Standard, Version 9.2, Part IV: Architecture Content Framework, Chapter 36: Building Blocks 3: The TOGAF Standard, Version 9.2, Part III: ADM Guidelines and Techniques, Chapter 31: Architecture Change Management : The TOGAF Standard, Version 9.2, Part II: Architecture Development Method (ADM), Chapter 23: Phase E: Opportunities and Solutions : The TOGAF Standard, Version 9.2, Part II: Architecture Development Method (ADM), Chapter 21: Phase F: Migration Planning : The TOGAF Standard, Version 9.2, Part II: Architecture Development Method (ADM), Chapter 18: Phase A: Architecture Vision : The TOGAF Standard, Version 9.2, Part III: ADM Guidelines and Techniques, Chapter 23: Architecture Principles
NEW QUESTION # 28
Please read this scenario prior to answering the question
Your role is that of a consultant to the Lead Enterprise Architect in a multinational automotive manufacturer.
The company has a corporate strategy that focuses on electrification of its portfolio, and it has invested heavily in a new shared car platform to use across all its brands. The company has four manufacturing facilities, one in North America, two in Europe, and one in Asia.
A challenge that the company is facing is to scale up the number of vehicles coming off the production line to meet customer demand, while maintaining quality. There are significant supply chain shortages for electronic components, which are impacting production. In response to this the company has taken on new suppliers and has also taken design and production of the battery pack in-house.
The company has a mature Enterprise Architecture practice. The TOGAF standard is used for developing the process and systems used to design, manufacture, and test the battery pack. The Chief Information Officer and the Chief Operating Officer co-sponsor the Enterprise Architecture program.
As part of putting the new battery pack into production, adjustments to the assembly processes need to be made. A pilot project has been completed at a single location. The Chief Engineer, sponsor of the activity, and the Architecture Board have approved the plan for implementation and migration at each plant.
Draft Architecture Contracts have been developed that detail the work needed to implement and deploy the new processes for each location. The company mixes internal teams with a few third-party contractors at the locations. The Chief Engineer has expressed concern that the deployment will not be consistent and of acceptable quality.
Refer to the scenario
The Lead Enterprise Architect has asked you to review the draft Architecture Contracts and recommend the best approach to address the Chief Engineer's concern.
Based on the TOGAF Standard, which of the following is the best answer?
- A. You review the contracts ensuring that they address project objectives, effectiveness metrics, acceptance criteria, and risk management. Third-party contracts must be legally enforceable. You recommend a schedule of compliance reviews at key points in the implementation process. You recommend that the Architecture Board reviews all deviations from the Architecture Contract and considers whether to grant a dispensation to allow the process to be customized for local needs.
- B. For changes undertaken by internal teams, you recommend a memorandum of understanding between the Architecture Board and the implementation organization. If a contract is issued to a contractor, you recommend that it is a fully enforceable legal contract. If a deviation from the Architecture Contract is found, you recommend that the Architecture Board grant a dispensation to allow the implementation organization to customize the process to meet their local needs.
- C. For changes requested by an internal team, you recommend a memorandum of understanding between the Architecture Board and the implementation organization. For contracts issued to third- party contractors, you recommend that it is a fully enforceable legal contract. You recommend that the Architecture Board reviews all deviations from the Architecture Contract and considers whether to grant a dispensation to allow the implementation organization to customize the process to meet their local needs.
- D. You recommend that the Architecture Contracts be used to manage the architecture governance processes across the locations. You recommend deployment of monitoring tools to assess the performance of each completed battery pack at each location and develop change requirements if necessary. If a deviation from the contract is detected, the Architecture Board should allow the Architecture Contract to be modified meet the local needs. In such cases they should issue a new Request for Architecture Work to implement a modification to the Architecture Definition.
Answer: A
Explanation:
According to the TOGAF Standard, Version 9.2, an Architecture Contract is a joint agreement between development partners and sponsors on the deliverables, quality, and fitness-for-purpose of an architecture1. It defines the scope, responsibilities, and governance of the architecture work, and ensures the alignment and compliance of the architecture with the business goals and objectives1.
In the scenario, the Lead Enterprise Architect has asked you to review the draft Architecture Contracts and recommend the best approach to address the Chief Engineer's concern about the consistency and quality of the deployment of the new processes for the battery pack production at each location.
The best answer is C, because it follows the guidelines and best practices for defining and using Architecture Contracts as described in the TOGAF Standard, Version 9.22. It ensures that the contracts cover the essential aspects of the project objectives, effectiveness metrics, acceptance criteria, and risk management, and that they are legally enforceable for third-party contractors. It also recommends a schedule of compliance reviews at key points in the implementation process, and a mechanism for handling any deviations from the Architecture Contract, involving the Architecture Board and the possibility of granting a dispensation to allow the process to be customized for local needs.
The other options are not correct because they either23:
A) For changes requested by an internal team, you recommend a memorandum of understanding between the Architecture Board and the implementation organization. For contracts issued to third-party contractors, you recommend that it is a fully enforceable legal contract. You recommend that the Architecture Board reviews all deviations from the Architecture Contract and considers whether to grant a dispensation to allow the implementation organization to customize the process to meet their local needs.: This option does not address the need to review the contracts to ensure that they address the project objectives, effectiveness metrics, acceptance criteria, and risk management. It also does not recommend a schedule of compliance reviews at key points in the implementation process. Moreover, it suggests that a memorandum of understanding is sufficient for internal teams, which may not be legally binding or enforceable.
B) For changes undertaken by internal teams, you recommend a memorandum of understanding between the Architecture Board and the implementation organization. If a contract is issued to a contractor, you recommend that it is a fully enforceable legal contract. If a deviation from the Architecture Contract is found, you recommend that the Architecture Board grant a dispensation to allow the implementation organization to customize the process to meet their local needs.: This option has the same problems as option A, and also implies that the Architecture Board should always grant a dispensation for any deviation, which may not be appropriate or desirable in some cases.
D) You recommend that the Architecture Contracts be used to manage the architecture governance processes across the locations. You recommend deployment of monitoring tools to assess the performance of each completed battery pack at each location and develop change requirements if necessary. If a deviation from the contract is detected, the Architecture Board should allow the Architecture Contract to be modified meet the local needs. In such cases they should issue a new Request for Architecture Work.: This option does not address the need to review the contracts to ensure that they address the project objectives, effectiveness metrics, acceptance criteria, and risk management. It also does not recommend a schedule of compliance reviews at key points in the implementation process. Moreover, it suggests that the Architecture Board should always allow the Architecture Contract to be modified for any deviation, which may not be appropriate or desirable in some cases. It also implies that a new Request for Architecture Work should be issued for each deviation, which may not be necessary or feasible.
References:
1: The TOGAF Standard, Version 9.2, Chapter 3: Definitions and Terminology, Section 3.1: Terms and Definitions
2: The TOGAF Standard, Version 9.2, Chapter 43: Architecture Contracts
3: The TOGAF Standard, Version 9.2, Chapter 44: Architecture Governance
NEW QUESTION # 29
Please read this scenario prior to answering the question
You are employed as an Enterprise Architect at a technology company, reporting directly to the Chief Enterprise Architect. The company supplies personnel and delivers cloud- based solutions to numerous government agencies.
The nature of the business is such that the data and the information stored on the company systems is the company's major asset and is highly confidential. The company employees work remotely and need constant access to the company systems, which is done by the public infrastructure. They use message encryption, secure internet connections using Virtual Private Networks (VPNs), and other standard security measures. The company provides computer security awareness training for all its staff.
The Chief Security Officer (CSO) has noted an increase in distributed denial of service (DDoS) attacks on companies with a similar profile. The CSO understands that even with thorough preparation, a major attack could stop employees from being able to do their jobs. This could lead to a large financial loss, damage to the company's reputation with customers, and employees being unable to work.
A risk assessment has been completed and the company has looked for cyber insurance that covers such attacks. The price for this insurance is very high. The CTO has decided not to get cyber insurance to cover such attacks.
The company follows the TOGAF standard as the method and guiding framework for its Enterprise Architecture (EA) practice. The Chief Technology Officer (CTO) is the sponsor of the activity. The practice uses an iterative approach for its architecture development.
This has enabled the decision makers to gain valuable insights into the different aspects of the business Please read this scenario prior to answering the question You have been asked to describe the steps you would take to strengthen the current architecture to improve data protection.
Based on the TOGAF standard which of the following is the best answer?
- A. You would hold an Architecture Compliance Review with the scope to examine the company's ability to respond to such attacks. You would identify the departments involved and have them nominate representatives. You would then tailor checklists to address the requirement for increased business continuity and resilience. You would circulate the checklists to the nominated representatives for them to complete. You would review the completed checklists, identifying and resolving issues. You would then determine and present your recommendations to the Architecture Board.
- B. You would run a planning exercise to assess the business continuity
requirements and analyze the current Enterprise Architecture for gaps. You create a formal change request related to business resilience and maintaining critical business functions. You would arrange a meeting of the Architecture Board to assess and approve the change request. Once approved you would create a new Request for Architecture Work to begin an ADM cycle to implement the changes. - C. You would request technology updates from existing suppliers that improve the company's capabilities to detect, react, and recover from an incident. You would run a simulated ransomware attack to evaluate the current Enterprise Architecture's resilience and recovery capabilities. Using the findings, you would perform a gap analysis of the current Enterprise Architecture, and prepare change requests to address identified gaps. You would document the changes implemented and add to the Architecture Repository.
- D. You would ensure that business value and cost of continuity measures are understood by key stakeholders, and that the company has in place up-to-date processes for managing change to the current Enterprise Architecture. You recommend that DDoS mitigation be addressed at the infrastructure level to ensure effective, scalable protection. Changes should be made to the baseline description of the Technology Architecture. The changes should be approved by the Architecture Board and implemented by change management techniques.
Answer: B
Explanation:
In this scenario, the CTO has not purchased cyber-insurance, the CSO is concerned about increased DDoS risk, and YOU (the EA) are asked "to describe the steps you would take to strengthen the current architecture to improve data protection." Because the company follows the TOGAF standard and uses an iterative ADM cycle, the correct response must:
Start with the risk/continuity concern
Use the formal TOGAF change management process
Lead to a Request for Architecture Work
Initiate a new ADM cycle to update the architecture properly
Ensure Architecture Board governance
Option B is the only answer that matches TOGAF's required process.
✔ Why Option B is correct (TOGAF-aligned)
Option B follows TOGAF's Architecture Change Management (Phase H) process:
Assess the business continuity requirements
- Correct: Phase H requires evaluating change triggers such as new risks, threats, or incidents.
- DDoS risk → business continuity concern → legitimate architecture change trigger.
Analyze the current architecture for gaps
- Correct: TOGAF Phase H requires assessing whether the current baseline architecture can support required resilience.
Create a formal Change Request
- Exactly correct: Phase H outputs Architecture Change Requests (ACRs) for significant changes.
- ACR includes description, rationale, and impact (in this case: resilience, continuity, and data protection).
Architecture Board reviews/approves the change request
- Correct: All major architecture changes must go through Architecture Governance.
Create a new Request for Architecture Work (RFAW)
- Required when the change is significant and needs a new ADM cycle.
- Strengthening data protection and business continuity DEFINITELY qualifies as a major change.
Begin a new ADM cycle to implement the changes
- Perfectly aligned with TOGAF's iterative approach:
Business continuity → update Technology Architecture → updated security patterns → updated Target Architecture.
This is exactly the TOGAF-prescribed method to strengthen an architecture when significant new risks appear.
Therefore, Option B is the correct and TOGAF-compliant answer.
✘ Why the other options are incorrect
A - Not TOGAF-aligned
Starts with vendors and simulations (not TOGAF-first steps).
No mention of Architecture Board or Change Management.
No Request for Architecture Work.
Gap analysis alone is not the first step for significant architectural risk.
C - Too narrow and skips TOGAF governance
Jumps straight to modifying the Technology Architecture baseline.
No Change Request, no RFAW, no ADM cycle initiation.
Recommends a solution ("DDoS mitigation at infrastructure level") before architectural assessment.
D - Misuses Architecture Compliance Review
Architecture Compliance Reviews check conformity to an existing architecture-not evaluate new risks or design resilience enhancements.
A compliance review is not the correct first step for addressing new threats.
NEW QUESTION # 30
Please read this scenario prior to answering the question
You have been appointed as Chief Enterprise Architect (CEA). reporting to the Chief Technical Officer (CTO), of a company established as a separate operating entity by a major automotive manufacturer. The mission of the company is to build a new industry leading unified technology and software platform for electric vehicles.
The company uses the TOGAF Standard as the basis for its Enterprise Architecture (EA) framework, and architecture development follows the purpose-based EA Capability model as described in the TOGAF Series Guide: A Practitioners'Approach to Developing Enterprise Architecture Following the TOGAF ADM.
An end-to-end Target Architecture has been completed with a roadmap for change over a five-year period. The new platform will be a cross-functional effort between hardware and software teams, with significant changes over the old platform. It is expected to be developed in several stages over three years. The EA team has inherited the architecture for the previous generation hardware and software automotive platform, some of which can be carried over to the new unified platform. The EA team has started to define the new platform, including defining which parts of the architecture to carry forward.
Enough of the Business Architecture has been defined, so that work can commence on the Information Systems and Technology Architectures. Those need to be defined to support the core business services that the company plans to provide. The core services will feature an innovative approach with swarm data generated by vehicles, paving the way for autonomous driving in the future.
The presentation and access to different variations of data that the company plans to offer through its platform pose an architecture challenge. The application portfolio and supporting infrastructure need to interact with various existing cloud services and data- Refer to the scenario You have been asked what approach should be taken to determine and organize the work to deliver the requested architectures?
Based on the TOGAF standard which of the following is the best answer?
- A. You will research leading data businesses, developing high-level Target Data, Application and Technology Architectures. You would review the Architecture Vision in order to estimate the level of detail, time, and breadth of the ADM cycle phases that will be needed to develop the architecture. You will identify and cost major work packages, and then develop an Architecture Roadmap. You would then seek approval by the Architecture Board and initiate the project.
- B. You would look outside the enterprise to research data models and application portfolios of leading big data businesses. You would develop just enough applications, data, and technology architecture to identify options. For each project this should include identification of candidate architecture and solution building blocks. You will identify solution providers, perform a readiness assessment, and assess the viability and fitness of the solution options. You will then document the draft Implementation and Migration plan.
- C. You will revisit ADM Phase A. identifying the stakeholders and creating a new Architecture Vision. You will update the Stakeholder map produced for the strategic architecture so it reflects the stakeholders who are now the most relevant to the projects that are to be developed. You would then ask the CTO to make some decisions about the Architecture Roadmap, and update the Implementation and Migration Plan to reflect the decisions.
- D. You would refer to the end-to-end Target Architecture for guidance and direction. The first objective should be to identify projects, dependencies and synergies, then prioritize before initiating the projects. You will develop high-level architecture descriptions. For each project you would estimate effort size, identify reference architectures, and candidate building blocks. You will identify the resource needs considering cost and value. You will document options, risks, and controls to enable viability analysis and trade-off with the stakeholders.
Answer: D
Explanation:
The Target Architecture is a description of the future state of the architecture that addresses the business goals and drivers, and satisfies the stakeholder requirements and concerns. The Target Architecture is developed through the Architecture Development Method (ADM), which is the core process of the TOGAF standard that guides the development and management of the enterprise architecture. The Target Architecture is typically divided into four domains: Business, Data, Application, and Technology. The Target Architecture also includes a roadmap for change, which defines the Transition Architectures, the Capability Increments, and the work packages that enable the transition from the Baseline Architecture to the Target Architecture12 The best answer is B, because it describes the approach that should be taken to determine and organize the work to deliver the requested architectures, which are the Information Systems and Technology Architectures. The answer covers the following steps:
Refer to the end-to-end Target Architecture for guidance and direction. The end-to-end Target Architecture provides the overall vision, scope, and objectives of the architecture work, and the alignment with the business strategy and goals. The end-to-end Target Architecture also provides the high-level definitions and principles for the four architecture domains, and the roadmap for change that outlines the major milestones and deliverables.
Identify projects, dependencies and synergies, then prioritize before initiating the projects. Projects are the units of work that implement the architecture work packages, which are the sets of actions or tasks that are required to implement a specific part of the architecture. Dependencies are the relationships and constraints that affect the order or priority of the projects, such as logical, temporal, or resource dependencies. Synergies are the benefits or advantages that result from the combination or coordination of the projects, such as cost savings, efficiency gains, or innovation opportunities. Prioritization is the process of ranking the projects according to their importance, urgency, or value, and assigning resources and schedules accordingly.
Develop high-level architecture descriptions. High-level architecture descriptions are the outputs of the architecture development phases (B, C, and D) of the ADM cycle, which describe the Business, Data, Application, and Technology Architectures in terms of the Architecture Building Blocks (ABBs) and the Solution Building Blocks (SBBs), which are reusable components of business, IT, or architectural capability. High-level architecture descriptions also include the Architecture Views, which are representations of the system of interest from the perspective of one or more stakeholders and their concerns.
For each project, estimate effort size, identify reference architectures, and candidate building blocks. Effort size is the measure of the amount of work, time, or resources required to complete a project. Effort size can be estimated using various techniques, such as analogy, expert judgment, parametric, or bottom-up. Reference architectures are standardized architectures that provide a common framework and vocabulary for a specific domain or industry. Reference architectures can be used as a source of best practices, patterns, and models for the architecture development. Candidate building blocks are the potential ABBs or SBBs that can be used to implement the architecture. Candidate building blocks can be identified from the Architecture Repository, which is a collection of architecture assets, such as models, patterns, principles, standards, and guidelines.
Identify the resource needs considering cost and value. Resource needs are the specifications and criteria that define the acceptable level and quality of the resources required to complete the project, such as human, financial, physical, or technological resources. Resource needs can be identified by analyzing the scope, complexity, and dependencies of the project, and the availability, capability, and suitability of the resources. Cost and value are the factors that influence the allocation and utilization of the resources, such as the budget, the return on investment, the benefits, or the risks.
Document options, risks, and controls to enable viability analysis and trade-off with the stakeholders. Options are the alternative ways of achieving the project objectives, such as different solutions, technologies, vendors, or approaches. Risks are the effects of uncertainty on the project objectives, such as threats or opportunities. Controls are the measures or actions that are taken to prevent, reduce, or mitigate the risks, such as policies, procedures, or standards. Viability analysis is the process of evaluating and comparing the options, risks, and controls, and determining the feasibility, suitability, and desirability of each option. Trade-off is the decision outcome that balances and reconciles the multiple, often conflicting, requirements and concerns of the stakeholders, and ensures alignment with the Architecture Vision and the Architecture Principles.
NEW QUESTION # 31
Scenario
Your role is that of an Enterprise Architect, reporting to the Chief Enterprise Architect, at a technology company.
The company uses the TOGAF standard as the method and guiding framework for its Enterprise Architecture (EA) practice. The Chief Technology Officer (CTO) is the sponsor of the activity. The EA practice uses an iterative approach for its architecture development. This has enabled the decision-makers to gain valuable insights into the different aspects of the business.
The nature of the business is such that the data and the information stored on the company systems is the company's major asset and is highly confidential. The company employees travel a lot for work and need to communicate over public infrastructure. They use message encryption, secure internet connections using Virtual Private Networks (VPNs), and other standard security measures. The company has provided computer security awareness training for all its staff. However, despite good education and system security, there is still a need to rely on third-party suppliers for infrastructure and software.
The Chief Security Officer (CSO) has noted an increase in ransomware (malicious software used in ransom demands) attacks on companies with a similar profile. The CSO recognizes that no matter how much is spent on education and support, the company could be a victim of a significant attack that could completely lock them out of their important data.
A risk assessment has been completed, and the company has looked for cyber insurance that covers ransomware. The price for this insurance is very high. The CTO recently saw a survey that said 1 out of 4 businesses that paid ransoms could not get their data back, and almost thesame number were able to recover the data without paying. The CTO has decided not to get cyber insurance to cover ransom payment.
You have been asked to describe the steps you would take to strengthen the current architecture to improve data protection.
Based on the TOGAF standard, which of the following is the best answer?
- A. You would monitor for technology updates from your existing suppliers that could enhance the company's capabilities to detect, react, and recover from an IT security incident. You would prepare and run a disaster recovery planning exercise for a ransomware attack and analyze the performance of the current Enterprise Architecture. Using the findings, you would prepare a gap analysis of the current Enterprise Architecture. You would prepare change requests to address identified gaps. You would add the changes implemented to the Architecture Repository.
- B. You would request an Architecture Compliance Review with the scope to examine the company's ability to respond to ransomware attacks. You would identify the departments involved and have them nominate representatives. You would then tailor checklists to address the requirement for increased resilience. You would circulate to the nominated representatives for them to complete. You would then review the completed checklists, identifying and resolving issues. You would then determine and present your recommendations.
- C. You would assess business continuity requirements and analyze the current Enterprise Architecture for gaps. You would recommend changes to address the situation and create a change request. You would engage the Architecture Board to assess and approve the change request. Once approved, you would create a new Request for Architecture Work to begin an ADM cycle to implement the changes.
- D. You would ensure that the company has in place up-to-date processes for managing change to the current Enterprise Architecture. Based on the scope of the concerns raised, you recommend that this be managed at the infrastructure level. Changes should be made to the baseline description of the Technology Architecture. The changes should be approved by the Architecture Board and implemented by change management techniques.
Answer: B
Explanation:
Comprehensive and Detailed Step-by-Step Explanation
Context of the Scenario
The scenario highlights significant risks due to ransomware attacks and the need to strengthen the company's Enterprise Architecture to improve data protection and resilience. TOGAF emphasizes the Architecture Compliance Review as a mechanism for ensuring the architecturemeets its objectives and addresses specific concerns such as security, resilience, and compliance with organizational goals.
The organization has already conducted a risk assessment but requires actionable steps to:
Address ransomware attack risks.
Increase the resilience of the Technology Architecture.
Ensure proper alignment with governance and compliance frameworks.
Option Analysis
Option A:
Strengths:
Highlights the need for up-to-date processes for managing changes in the Enterprise Architecture.
Recognizes the importance of governance through the Architecture Board and change management techniques.
Weaknesses:
The approach focuses solely on the Technology Architecture baseline but does not address the need for specific steps such as compliance review, gap analysis, or tailored resilience measures for ransomware risks.
It provides a broad and generic approach rather than a targeted plan for ransomware and data protection issues.
Conclusion: Incorrect. While it adheres to governance processes, it lacks specific actions to improve resilience and address the immediate security concerns.
Option B:
Strengths:
Proposes an Architecture Compliance Review, which is a core TOGAF process used to evaluate architecture implementation against defined objectives, ensuring it is fit for purpose.
Involves identifying stakeholders (departments) and tailoring checklists specific to ransomware resilience.
Emphasizes issue identification and resolution through structured review processes.
Weaknesses:
Does not explicitly address longer-term updates to the Enterprise Architecture, but this can be inferred as a next step following compliance recommendations.
Conclusion: Correct. This is the most suitable approach based on TOGAF principles, as it uses an established process to evaluate and improve the architecture's resilience.
Option C:
Strengths:
Includes monitoring for updates from suppliers to enhance detection and recovery capabilities, which is relevant to addressing ransomware risks.
Proposes a gap analysis to identify shortcomings in the current Enterprise Architecture and recommends addressing gaps through change requests.
Incorporates disaster recovery planning exercises, which are useful for testing resilience.
Weaknesses:
While thorough, the approach lacks the Architecture Compliance Review process, which is a more structured way to ensure the architecture meets resilience requirements.
Monitoring suppliers and running disaster recovery exercises are operational steps rather than strategic architectural improvements.
Conclusion: Incorrect. While it includes valid activities, it does not adhere to TOGAF's structured approach for architecture assessment and compliance.
Option D:
Strengths:
Proposes analyzing business continuity requirements and assessing the architecture for gaps, which is relevant to the scenario.
Suggests initiating an ADM cycle to address gaps, which aligns with TOGAF principles.
Weaknesses:
Focusing on initiating a new ADM cycle may be premature, as the immediate priority is to evaluate the existing architecture and address specific resilience concerns.
Does not mention compliance review or tailored resilience measures for ransomware attacks, which are central to the scenario.
Conclusion: Incorrect. It proposes a broader approach that may not adequately address the immediate concerns highlighted by the CSO.
TOGAF Reference
Architecture Compliance Review: A structured process used to evaluate whether an architecture meets the stated goals, objectives, and requirements (TOGAF 9.2, Chapter 19). It is particularly useful for identifying and addressing resilience requirements in scenarios involving security risks.
Stakeholder Engagement: Identifying and involving stakeholders (e.g., departments) is a critical part of architecture governance and compliance review (TOGAF 9.2, Section 24.2).
Change Management: The Architecture Compliance Review supports identifying necessary changes, which are then managed through governance and change management processes (TOGAF 9.2, Section 21.6).
By choosing Option B, you align with TOGAF's structured approach to compliance, resilience, and addressing security concerns.
NEW QUESTION # 32
Please read this scenario prior to answering the question
You are working as Chief Enterprise Architect at a large Internet company. The company has many divisions, ranging from cloud to logistics. The company has grown rapidly, expanding from initially selling physical books and media to a range of services including an online marketplace, live-streaming. eBooks. and cloud services.
Overall management of the numerous divisions has become challenging. Recent high-profile projects have overrun on budget and under delivered, damaging the company's reputation, and adversely impacting its share price. There is a widely held view within the executive management that the organization structure has played a major role in these project failures.
The company has an established Enterprise Architecture program based on the TOGAF standard, sponsored jointly by the Chief Executive Officer (CEO) and Chief Information Officer (CIO). The CEO has decided that the company needs to reorganize its divisions around artificial intelligence and machine learning with a focus on automation. The CEO has worked with the Enterprise Architects to create a strategic architecture for the reorganization, including an Architecture Vision, together with definitions for the four domain architectures. This sets out an ambitious vision of the future of the company over a three-year period. This includes a set of work packages and includes three distinct transformations.
The CIO has made it clear that prior to the approval of the detailed Implementation and Migration plan, the EAteam will need to assess the risks associated with the proposed architecture. He has received concerns from key stakeholders across the company that the proposed reorganization may be too ambitious and there is doubt whether it can produce sufficient value to warrant the risks.
Refer to the scenario
You have been asked to recommend an approach to satisfy these concerns. Based on the TOGAF Standard, which of the following is the best answer?
- A. Before preparing the detailed Implementation and Migration plan, the Enterprise
- B. The Enterprise Architects should bring together information about potential approaches and produce several alternative target transition architectures. They should then investigate the different architecture alternatives and discuss these with stakeholders using the Architecture Alternatives and Trade-offs technique. Once the target architecture has been selected, it should be analyzed using a state evolution table to determine the Transition Architectures. A value realization process should then be established to ensure that the concerns raised are addressed.
- C. The Enterprise Architects should evaluate the organization's readiness to undergo change. This will allow the risks associated with the transformations to be identified, classified, and mitigated for. This should include identifying dependencies between the set of changes, including gaps and work packages. It will also identify improvement actions to be worked into the Implementation and Migration Plan. The business value, effort, and risk associated for each transformation should be determined.
- D. Establishing interoperability in alignment with the corporate operating model will ensure risks are minimized. The Enterprise Architects should apply an interoperability analysis to evaluate any potential issues across the architecture. This should include the development of a matrix showing the interoperability requirements. These can then be included within the transformation strategy embedded in the target transition architectures. The Enterprise Architects should then finalize the Architecture Roadmap and the Implementation and Migration Plan.
Answer: C
Explanation:
Architects should review and consolidate the gap analysis results from Phases B to This will identify the transformations required to achieve the proposed Target Architecture. The Enterprise Architects should then assess the readiness of the organization to undergo change and determine an overall direction to address and mitigate risks identified. The Transition Architecture should then be planned to use a state evolution table.
Explanation:
The Business Transformation Readiness Assessment is a technique that can be used to evaluate the readiness of the organization to undergo change and to identify the actions needed to increase the likelihood of a successful business transformation. This technique can help to address the concerns of the key stakeholders about the risks and value of the proposed reorganization. The technique involves assessing the following aspects of the organization: vision, commitment, capacity, capability, culture, and communication. Based on the assessment, the risks associated with the transformations can be identified, classified, and mitigated for. The technique also helps to identify the dependencies between the set of changes, including gaps and work packages, and the improvement actions to be worked into the Implementation and Migration Plan. The technique also supports the determination of the business value, effort, and risk associated for each transformation, which can be used to prioritize and sequence the work packages and the Transition Architectures1 References: 1: The TOGAF Standard, Version 9.2, Part III: ADM Guidelines and Techniques, Chapter 27: Business Transformation Readiness Assessment
NEW QUESTION # 33
Please read this scenario prior to answering the question
You have been appointed as Chief Enterprise Architect (CEA). reporting to the Chief Technical Officer (CTO), of a company established as a separate operating entity by a major automotive manufacturer. The mission of the company is to build a new industry leading unified technology and software platform for electric vehicles.
The company uses the TOGAF Standard as the basis for its Enterprise Architecture (EA) framework, and architecture development follows the purpose-based EA Capability model as described in the TOGAF Series Guide: A Practitioners'Approach to Developing Enterprise Architecture Following the TOGAF® ADM.
An end-to-end Target Architecture has been completed with a roadmap for change over a five-year period. The new platform will be a cross-functional effort between hardware and software teams, with significant changes over the old platform. It is expected to be developed in several stages over three years. The EA team has inherited the architecture for the previous generation hardware and software automotive platform, some of which can be carried over to the new unified platform. The EA team has started to define the new platform, including defining which parts of the architecture to carry forward.
Enough of the Business Architecture has been defined, so that work can commence on the Information Systems and Technology Architectures. Those need to be defined to support the core business services that the company plans to provide. The core services will feature an innovative approach with swarm data generated by vehicles, paving the way for autonomous driving in the future.
The presentation and access to different variations of data that the company plans to offer through its platform pose an architecture challenge. The application portfolio and supporting infrastructure need to interact with various existing cloud services and data- Refer to the scenario You have been asked what approach should be taken to determine and organize the work to deliver the requested architectures?
Based on the TOGAF standard which of the following is the best answer?
- A. You will research leading data businesses, developing high-level Target Data, Application and Technology Architectures. You would review the Architecture Vision in order to estimate the level of detail, time, and breadth of the ADM cycle phases that will be needed to develop the architecture. You will identify and cost major work packages, and then develop an Architecture Roadmap. You would then seek approval by the Architecture Board and initiate the project.
- B. You would look outside the enterprise to research data models and application portfolios of leading big data businesses. You would develop just enough applications, data, and technology architecture to identify options. For each project this should include identification of candidate architecture and solution building blocks. You will identify solution providers, perform a readiness assessment, and assess the viability and fitness of the solution options. You will then document the draft Implementation and Migration plan.
- C. You will revisit ADM Phase A. identifying the stakeholders and creating a new Architecture Vision. You will update the Stakeholder map produced for the strategic architecture so it reflects the stakeholders who are now the most relevant to the projects that are to be developed. You would then ask the CTO to make some decisions about the Architecture Roadmap, and update the Implementation and Migration Plan to reflect the decisions.
- D. You would refer to the end-to-end Target Architecture for guidance and direction. The first objective should be to identify projects, dependencies and synergies, then prioritize before initiating the projects. You will develop high-level architecture descriptions. For each project you would estimate effort size, identify reference architectures, and candidate building blocks. You will identify the resource needs considering cost and value. You will document options, risks, and controls to enable viability analysis and trade-off with the stakeholders.
Answer: D
Explanation:
The Target Architecture is a description of the future state of the architecture that addresses the business goals and drivers, and satisfies the stakeholder requirements and concerns. The Target Architecture is developed through the Architecture Development Method (ADM), which is the core process of the TOGAF standard that guides the development and management of the enterprise architecture. The Target Architecture is typically divided into four domains: Business, Data, Application, and Technology. The Target Architecture also includes a roadmap for change, which defines the Transition Architectures, the Capability Increments, and the work packages that enable the transition from the Baseline Architecture to the Target Architecture12 The best answer is B, because it describes the approach that should be taken to determine and organize the work to deliver the requested architectures, which are the Information Systems and Technology Architectures. The answer covers the following steps:
Refer to the end-to-end Target Architecture for guidance and direction. The end-to-end Target Architecture provides the overall vision, scope, and objectives of the architecture work, and the alignment with the business strategy and goals. The end-to-end Target Architecture also provides the high-level definitions and principles for the four architecture domains, and the roadmap for change that outlines the major milestones and deliverables.
Identify projects, dependencies and synergies, then prioritize before initiating the projects. Projects are the units of work that implement the architecture work packages, which are the sets of actions or tasks that are required to implement a specific part of the architecture. Dependencies are the relationships and constraints that affect the order or priority of the projects, such as logical, temporal, or resource dependencies. Synergies are the benefits or advantages that result from the combination or coordination of the projects, such as cost savings, efficiency gains, or innovation opportunities. Prioritization is the process of ranking the projects according to their importance, urgency, or value, and assigning resources and schedules accordingly.
Develop high-level architecture descriptions. High-level architecture descriptions are the outputs of the architecture development phases (B, C, and D) of the ADM cycle, which describe the Business, Data, Application, and Technology Architectures in terms of the Architecture Building Blocks (ABBs) and the Solution Building Blocks (SBBs), which are reusable components of business, IT, or architectural capability. High-level architecture descriptions also include the Architecture Views, which are representations of the system of interest from the perspective of one or more stakeholders and their concerns.
For each project, estimate effort size, identify reference architectures, and candidate building blocks. Effort size is the measure of the amount of work, time, or resources required to complete a project. Effort size can be estimated using various techniques, such as analogy, expert judgment, parametric, or bottom-up. Reference architectures are standardized architectures that provide a common framework and vocabulary for a specific domain or industry. Reference architectures can be used as a source of best practices, patterns, and models for the architecture development. Candidate building blocks are the potential ABBs or SBBs that can be used to implement the architecture. Candidate building blocks can be identified from the Architecture Repository, which is a collection of architecture assets, such as models, patterns, principles, standards, and guidelines.
Identify the resource needs considering cost and value. Resource needs are the specifications and criteria that define the acceptable level and quality of the resources required to complete the project, such as human, financial, physical, or technological resources. Resource needs can be identified by analyzing the scope, complexity, and dependencies of the project, and the availability, capability, and suitability of the resources. Cost and value are the factors that influence the allocation and utilization of the resources, such as the budget, the return on investment, the benefits, or the risks.
Document options, risks, and controls to enable viability analysis and trade-off with the stakeholders. Options are the alternative ways of achieving the project objectives, such as different solutions, technologies, vendors, or approaches. Risks are the effects of uncertainty on the project objectives, such as threats or opportunities. Controls are the measures or actions that are taken to prevent, reduce, or mitigate the risks, such as policies, procedures, or standards. Viability analysis is the process of evaluating and comparing the options, risks, and controls, and determining the feasibility, suitability, and desirability of each option. Trade-off is the decision outcome that balances and reconciles the multiple, often conflicting, requirements and concerns of the stakeholders, and ensures alignment with the Architecture Vision and the Architecture Principles.
NEW QUESTION # 34
Please read this scenario prior to answering the question
Your role is that of a consultant to the Lead Enterprise Architect in a multinational automotive manufacturer.
The company has a corporate strategy that focuses on electrification of its portfolio, and it has invested heavily in a new shared car platform to use across all its brands. The company has four manufacturing facilities, one in North America, two in Europe, and one in Asia.
A challenge that the company is facing is to scale up the number of vehicles coming off the production line to meet customer demand, while maintaining quality. There are significant supply chain shortages for electronic components, which are impacting production. In response to this the company has taken on new suppliers and has also taken design and production of the battery pack in-house.
The company has a mature Enterprise Architecture practice. The TOGAF standard is used for developing the process and systems used to design, manufacture, and test the battery pack. The Chief Information Officer and the Chief Operating Officer co-sponsor the Enterprise Architecture program.
As part of putting the new battery pack into production, adjustments to the assembly processes need to be made. A pilot project has been completed at a single location. The Chief Engineer, sponsor of the activity, and the Architecture Board have approved the plan for implementation and migration at each plant.
Draft Architecture Contracts have been developed that detail the work needed to implement and deploy the new processes for each location. The company mixes internal teams with a few third-party contractors at the locations. The Chief Engineer has expressed concern that the deployment will not be consistent and of acceptable quality.
Refer to the scenario
The Lead Enterprise Architect has asked you to review the draft Architecture Contracts and recommend the best approach to address the Chief Engineer's concern.
Based on the TOGAF Standard, which of the following is the best answer?
- A. You review the contracts ensuring that they address project objectives, effectiveness metrics, acceptance criteria, and risk management. Third-party contracts must be legally enforceable. You recommend a schedule of compliance reviews at key points in the implementation process. You recommend that the Architecture Board reviews all deviations from the Architecture Contract and considers whether to grant a dispensation to allow the process to be customized for local needs.
- B. For changes undertaken by internal teams, you recommend a memorandum of understanding between the Architecture Board and the implementation organization. If a contract is issued to a contractor, you recommend that it is a fully enforceable legal contract. If a deviation from the Architecture Contract is found, you recommend that the Architecture Board grant a dispensation to allow the implementation organization to customize the process to meet their local needs.
- C. For changes requested by an internal team, you recommend a memorandum of understanding between the Architecture Board and the implementation organization. For contracts issued to third- party contractors, you recommend that it is a fully enforceable legal contract. You recommend that the Architecture Board reviews all deviations from the Architecture Contract and considers whether to grant a dispensation to allow the implementation organization to customize the process to meet their local needs.
- D. You recommend that the Architecture Contracts be used to manage the architecture governance processes across the locations. You recommend deployment of monitoring tools to assess the performance of each completed battery pack at each location and develop change requirements if necessary. If a deviation from the contract is detected, the Architecture Board should allow the Architecture Contract to be modified meet the local needs. In such cases they should issue a new Request for Architecture Work to implement a modification to the Architecture Definition.
Answer: A
Explanation:
According to the TOGAF Standard, Version 9.2, an Architecture Contract is a joint agreement between development partners and sponsors on the deliverables, quality, and fitness-for-purpose of an architecture1. It defines the scope, responsibilities, and governance of the architecture work, and ensures the alignment and compliance of the architecture with the business goals and objectives1.
In the scenario, the Lead Enterprise Architect has asked you to review the draft Architecture Contracts and recommend the best approach to address the Chief Engineer's concern about the consistency and quality of the deployment of the new processes for the battery pack production at each location.
The best answer is C, because it follows the guidelines and best practices for defining and using Architecture Contracts as described in the TOGAF Standard, Version 9.22. It ensures that the contracts cover the essential aspects of the project objectives, effectiveness metrics, acceptance criteria, and risk management, and that they are legally enforceable for third-party contractors. It also recommends a schedule of compliance reviews at key points in the implementation process, and a mechanism for handling any deviations from the Architecture Contract, involving the Architecture Board and the possibility of granting a dispensation to allow the process to be customized for local needs.
The other options are not correct because they either23:
A . For changes requested by an internal team, you recommend a memorandum of understanding between the Architecture Board and the implementation organization. For contracts issued to third-party contractors, you recommend that it is a fully enforceable legal contract. You recommend that the Architecture Board reviews all deviations from the Architecture Contract and considers whether to grant a dispensation to allow the implementation organization to customize the process to meet their local needs.: This option does not address the need to review the contracts to ensure that they address the project objectives, effectiveness metrics, acceptance criteria, and risk management. It also does not recommend a schedule of compliance reviews at key points in the implementation process. Moreover, it suggests that a memorandum of understanding is sufficient for internal teams, which may not be legally binding or enforceable.
B . For changes undertaken by internal teams, you recommend a memorandum of understanding between the Architecture Board and the implementation organization. If a contract is issued to a contractor, you recommend that it is a fully enforceable legal contract. If a deviation from the Architecture Contract is found, you recommend that the Architecture Board grant a dispensation to allow the implementation organization to customize the process to meet their local needs.: This option has the same problems as option A, and also implies that the Architecture Board should always grant a dispensation for any deviation, which may not be appropriate or desirable in some cases.
D . You recommend that the Architecture Contracts be used to manage the architecture governance processes across the locations. You recommend deployment of monitoring tools to assess the performance of each completed battery pack at each location and develop change requirements if necessary. If a deviation from the contract is detected, the Architecture Board should allow the Architecture Contract to be modified meet the local needs. In such cases they should issue a new Request for Architecture Work.: This option does not address the need to review the contracts to ensure that they address the project objectives, effectiveness metrics, acceptance criteria, and risk management. It also does not recommend a schedule of compliance reviews at key points in the implementation process. Moreover, it suggests that the Architecture Board should always allow the Architecture Contract to be modified for any deviation, which may not be appropriate or desirable in some cases. It also implies that a new Request for Architecture Work should be issued for each deviation, which may not be necessary or feasible.
Reference:
1: The TOGAF Standard, Version 9.2, Chapter 3: Definitions and Terminology, Section 3.1: Terms and Definitions
2: The TOGAF Standard, Version 9.2, Chapter 43: Architecture Contracts
3: The TOGAF Standard, Version 9.2, Chapter 44: Architecture Governance
NEW QUESTION # 35
Please read this scenario prior to answering the question
You are working as an Enterprise Architect at a large supermarket. The company runs many retail stores, as well as an online grocery shop. Many of the stores used to remain open 24/7, but the number has decreased in recent years. Instead, they now focus on fulfilling online orders during the night.
The company has a mature Enterprise Architecture (EA) practice and uses the TOGAF standard for its architecture development method. The EA practice is involved in all aspects of the business, with oversight provided by an Architecture Board with representatives from different parts of the business. The EA program is sponsored by the Chief Information Officer (CIO).
Each store uses a standard method to track sales and inventory. This involves sending accurate timely sales data to a central Al-based inventory management system that can predict demand, adjust stock levels and automate reordering. The central inventory management system is housed at the company's central data center.
The company has bought a major rival. The Chief Executive Officer believes that a merger will enable growth through combined offerings and cost savings. The decision has been taken to fully integrate the two organizations, including merging retail operations and systems. This means that duplicated systems will be replaced with one standard retail management system. Also, the company will reduce the number of applications that are used. The CIO expects significant savings will be achieved by implementing these changes across the newly merged company.
One improvement that the rival has successfully implemented is the use of hand-held devices within stores, for both customers and staff. This has increased both customer and staff employee satisfaction due to the time savings this has brought. The CIO has given the go-ahead to roll out the devices in all stores but has stated that training on how to use the hand-held devices should be brief because there are a lot of employees, many of whom are part-time.
The Request for Architecture Work to oversee the merger has been approved. The project has been scoped and you have been assigned to work on it. Your role includes managing the architecture for the retail stores.
Refer to the scenario
You have been asked to confirm the most relevant architecture principles for the transformation.
Based on the TOGAF Standard, which of the following is the best answer?
[Note: The sequence of the principles listed in each answer does not matter. You should assume the company follows the set of principles that are provided in the TOGAF Standard, ADM Techniques, Architecture Principles chapter. You may need to refer to section 2.6 located in ADM Techniques within the reference text to answer this question.]
- A. Common Use Applications, Data is an Asset, Data is Accessible, Ease of Use, Business Continuity
- B. Common Vocabulary and Data Definitions, Compliance with the Law, Requirements Based Change, Responsive Change Management, Data Security
- C. Maximize Benefit to the Enterprise, Common Use Applications, Data is an Asset, Responsive Change Management, Technology Independence
- D. Control Technical Diversity, Interoperability, Data is an Asset, Data is Shared, Business Continuity
Answer: C
Explanation:
Key aspects of the scenario:
Business Objective:
A merger is happening to combine offerings, reduce costs, and achieve operational efficiency.
The goal includes fully integrating retail operations and systems, replacing duplicated systems, and reducing the number of applications used.
Technological Improvements:
A central AI-based inventory system is in place.
Hand-held devices for stores have improved customer and staff satisfaction and increased efficiency.
Scope of Architecture Work:
Integrating the merged systems.
Managing retail architecture to optimize operations.
TOGAF Alignment:
TOGAF principles aim to ensure the architecture supports business transformation effectively while aligning with governance and best practices.
Best answer analysis:
Option 1:
Maximize Benefit to the Enterprise: Aligns with the merger goals of cost reduction and efficiency.
Common Use Applications: Matches the goal to reduce duplicated systems.
Data is an Asset: Central AI system depends on accurate and reliable data.
Responsive Change Management: Necessary to support the transition and manage organizational impacts.
Technology Independence: Encourages selecting flexible, scalable solutions post-merger.
This option comprehensively aligns with the scenario.
Option 2:
Control Technical Diversity: Important but less emphasized than cost reduction and application unification.
Interoperability: Relevant, but less critical compared to principles addressing business value.
Data is an Asset: Relevant.
Data is Shared: Implied in centralized inventory but not directly stated.
Business Continuity: Important but not the main focus here.
This option partially fits but lacks emphasis on business outcomes.
Option 3:
Common Vocabulary and Data Definitions: Indirectly helpful but not central to the transformation.
Compliance with the Law: Always critical, but no explicit legal issues are mentioned.
Requirements-Based Change: General principle but not transformation-specific.
Responsive Change Management: Relevant.
Data Security: Important but not a central concern in the scenario.
This option focuses more on governance and less on merger goals.
Option 4:
Common Use Applications: Relevant to reducing duplicate systems.
Data is an Asset: Relevant.
Data is Accessible: Fits with AI system and handheld devices but is a subset of "Data is an Asset." Ease of Use: Relevant to handheld devices but not a core transformation principle.
Business Continuity: Important but secondary to cost and efficiency.
This option focuses more on usability and accessibility rather than transformation objectives.
NEW QUESTION # 36
Please read this scenario prior to answering the question
You have been appointed as senior architect working for an autonomous driving technology development company. The mission of the company is to build an industry leading unified technology and software platform to support connected cars and autonomous driving.
The company uses the TOGAF Standard as the basis for its Enterprise Architecture (EA) framework. Architecture development within the company follows the purpose-based EA Capability model as described in the TOGAF Series Guide: A Practitioners'Approach to Developing Enterprise Architecture Following the TOGAF ADM.
An architecture to support strategy has been completed defining a long-range Target Architecture with a roadmap spanning five years. This has identified the need for a portfolio of projects over the next two years. The portfolio includes development of travel assistance systems using swarm data from vehicles on the road.
The current phase of architecture development is focused on the Business Architecture which needs to support the core travel assistance services that the company plans to provide. The core services will manage and process the swarm data generated by vehicles, paving the way for autonomous driving in the future.
The presentation and access to different variations of data that the company plans to offer through its platform poses an architecture challenge. The application portfolio needs to interact securely with various third-party cloud services, and V2X (Vehicle-to-Everything) service providers in many countries to be able to manage the data at scale. The security of V2X is a key concern for the stakeholders. Regulators have stated that the user's privacy be always protected, for example, so that the drivers' journey cannot be tracked or reconstructed by compiling data sent or received by the car.
Refer to the scenario
You have been asked to describe the risk and security considerations you would include in the current phase of the architecture development?
Based on the TOGAF standard which of the following is the best answer?
- A. You will perform a qualitative risk assessment for the data assets exchanged with partners. This will deliver a set of priorities, high to medium to low, based on identified threats, the likelihood of occurrence, and the impact if it did occur. Using the priorities, you would then develop a Business Risk Model which will detail the risk strategy including classifications to determine what mitigation is enough.
- B. You will create a security domain model so that assets with the same level can be managed under one security policy. Since data is being shared across partners, you will establish a security federation to include them. This would include contractual arrangements, and a definition of the responsibility areas for the data exchanged, as well as security implications. You would undertake a risk assessment determining risks relevant to specific data assets.
- C. You will focus on the relationship with the third parties required for the travel assistance systems and define a trust framework. This will describe the relationship with each party. Digital certificates are a key part of the framework and will be used to create trust between parties. You will monitor legal and regulatory changes across all the countries to keep the trust framework in compliance.
- D. You will focus on data quality as it is a key factor in risk management. You will identify the datasets that need to be safeguarded. For each dataset, you will assign ownership and responsibility for the quality of data needs. A security classification will be defined and applied to each dataset. The dataset owner will then be able to authorize processes that are trusted for a certain activity on the dataset under certain circumstances.
Answer: B
NEW QUESTION # 37
......
100% Reliable Microsoft OGEA-102 Exam Dumps Test Pdf Exam Material: https://pass4sure.examcost.com/OGEA-102-practice-exam.html

