Summer Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

TOGAF Enterprise Architecture Part 2 Exam (English)

Last Update 23 hours ago Total Questions : 42

The TOGAF Enterprise Architecture Part 2 Exam (English) content is now fully updated, with all current exam questions added 23 hours ago. Deciding to include OGEA-102 practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our OGEA-102 exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these OGEA-102 sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any TOGAF Enterprise Architecture Part 2 Exam (English) practice test comfortably within the allotted time.

Question # 1

Please read this scenario prior to answering the question

Your role is that of a consultant to the Lead Enterprise Architect in a multinational automotive manufacturer.

The company has a corporate strategy that focuses on electrification of its portfolio, and it has invested

heavily in a new shared car platform to use across all its brands. The company has four manufacturing

facilities, one in North America, two in Europe, and one in Asia.

A challenge that the company is facing is to scale up the number of vehicles coming off the production line to meet customer demand, while maintaining quality. There are significant supply chain shortages for electronic components, which are impacting production. In response to this the company has taken on new suppliers and has also taken design and production of the battery pack in-house.

The company has a mature Enterprise Architecture practice. The TOGAF standard is used for developing

the process and systems used to design, manufacture, and test the battery pack. The Chief Information

Officer and the Chief Operating Officer co-sponsor the Enterprise Architecture program.

As part of putting the new battery pack into production, adjustments to the assembly processes need to be made. A pilot project has been completed at a single location. The Chief Engineer, sponsor of the activity, and the Architecture Board have approved the plan for implementation and migration at each plant.

Draft Architecture Contracts have been developed that detail the work needed to implement and deploy the new processes for each location. The company mixes internal teams with a few third-party contractors at the locations. The Chief Engineer has expressed concern that the deployment will not be consistent and of acceptable quality.

Refer to the scenario

The Lead Enterprise Architect has asked you to review the draft Architecture Contracts and recommend the best approach to address the Chief Engineer ' s concern.

Based on the TOGAF Standard, which of the following is the best answer?

A.

For changes requested by an internal team, you recommend a memorandum of understandingbetween the Architecture Board and the implementation organization. For contracts issued to third-party contractors, you recommend that it is a fully enforceable legal contract. You recommend thatthe Architecture Board reviews all deviations from the Architecture Contract and considers whether togrant a dispensation to allow the implementation organization

B.

For changes undertaken by internal teams, you recommend a memorandum of understandingbetween the Architecture Board and the implementation organization. If a contract is issued to acontractor, you recommend that it is a fully enforceable legal contract. If a deviation from theArchitecture Contract is found, you recommend that the Architecture Board grant a dispensation toallow the implementation organization to customize the process to meet

C.

You review the contracts ensuring that they address project objectives, effectiveness metrics,acceptance criteria, and risk management. Third-party contracts must be legally enforceable. Yourecommend a schedule of compliance reviews at key points in the implementation process. Yourecommend that the Architecture Board reviews all deviations from the Architecture Contract andconsiders whether to grant a dispensation to allow the process to be

D.

You recommend that the Architecture Contracts be used to manage the architecture governanceprocesses across the locations. You recommend deployment of monitoring tools to assess theperformance of each completed battery pack at each location and develop change requirements ifnecessary. If a deviation from the contract is detected, the Architecture Board should allow theArchitecture Contract to be modified meet the local needs. In such cases

Question # 2

Please read this scenario prior to answering the question

You are the Lead Enterprise Architect at a major agribusiness company. The company ' s main harvest is lentils, a highly valued food grown worldwide. The lentil parasite, broomrape, has been an increasing concern for many years and is now becoming resistant to chemical controls. In addition, changes in climate favor the propagation and growth of the parasite. As a result, the parasite cannot realistically be exterminated, and it has become pandemic, with lentil yields falling globally.

In response to the situation, the CEO has decided that the lentil fields will be used for another harvest. The company will also cease to process third-party lentils and will repurpose its processing plants. Thus, the target market will change, and the end-products will be different and more varied.

The company has recently established an Enterprise Architecture practice based on the TOGAF standard as method and guiding framework. The CIO is the sponsor of the activity. A formal request for architecture change has been approved. At this stage there is no fixed scope, shared vision, or objectives.

Refer to the scenario

You have been asked to propose the best approach for architecture development to realize the CEO ' s change in direction for the company.

Based on the TOGAF standard which of the following is the best answer?

A.

You propose that this engagement define the baseline Technology Architecture first in order to assess the current infrastructure capacity and capability for the company. Then the focus should be on transition planning and incremental architecture deployment. This will identify requirements to ensure that the projects are sequenced in an optimal fashion so as to realize the change.

B.

You propose that the team uses the architecture definition document and focus on architecture development starting simultaneously phases B, C and D. This is because the CEO has identified the need to change. This will ensure that the change can be defined in a structured manner and address the requirements needed to realize the change.

C.

You propose that the team focus on architecture definition including development of business models, with emphasis on defining the change parameters to support this new business strategy that the CEO has identified. Once understood, the team will be in the best position to identify the requirements, drivers, issues, and constraints for the change.

D.

You propose that the priority is to produce a new Request for Architecture Work leading to development of a new Architecture Vision. The trade-off method should be applied to identify and select an architecture satisfying the stakeholders. For an efficient change the EA team should be aligned with the organization ' s planning, budgeting, operational, and change processes.

Question # 3

Please read this scenario prior to answering the question

You are employed as an Enterprise Architect within a multinational company. The

company has been very successful and has been buying companies around the

world. This has led to a growing number of manufacturing divisions in various

locations with a complex supply chain.

The top management recently expressed concerns about the company ' s effectiveness

because of its multiple data centers and duplicate applications. The EA team has

been working on a project to solve this issue. An analysis shows that supply chain

issues have led to not enough products being produced to meet all the customer

demand.

A strategic architecture has been defined to help meet customer demand and manage

the supply chain more effectively. The strategic architecture involves combining

different Enterprise Resource Planning (ERP) applications that are currently used

separately in the company ' s production sites.

Each division has finished the Architecture Definition documentation to address their

own specific manufacturing needs. The Enterprise Architects have agreed an overall

strategy for the migration. They have defined a set of work packages that address the

gaps found. They have defined the intermediate architectural states between the

Baseline and Target architecture to add a new ERP environment into the company.

Because of the risks posed by this change from the current environment, the

architects have recommended that a phased approach should be taken to implement

the target architecture with several stages of change. They have created a draft

roadmap with the implementation process estimated to take over two years.

The company has an established Enterprise Architecture (EA) practice and follows the

TOGAF Architecture Development Method. The company also uses various

management frameworks such as business planning, project/portfolio management,

and operations management. The EA program is sponsored by the Chief Information

Officer (CIO). In your role as an Enterprise Architect within the EA team, you work

closely with the important stakeholders from the various divisions within the company.

Refer to the scenario

You have been assigned to plan the next steps for the migration. Which approach will

you choose?

Based on the TOGAF standard which of the following is the best answer?

A.

You finalize the Architecture Definition documentation with updates to reflectthe implementation approach. You ensure that Implementation and MigrationPlan is consistent with the chosen approach. You identify the resourcesneeded to undertake the development projects. You would then produce anImplementation Governance Model to manage the lessons learned beforefinishing the plan. You ensure that the lessons learned are applied to theImplement

B.

You estimate the business value for each project by applying the BusinessValue Assessment Technique to prioritize the migration projects and projectsteps. The assessment should focus on return on investment and criteria forevaluating performance to track the progress of the architecturetransformation. You would confirm and plan a series of Transition Architecturephases using a table of Architecture Definition Increments that lists theprojec

C.

You will focus on project selection. You make sure that the Implementation andMigration plan aligns with the other management frameworks in use in thecompany. Next, you assign a value to each work package, taking into accountthe resources available and how they fit into the overall strategy. Using thesework packages, you estimate resource requirements and timings. You thenselect which projects will be included in the Implementation and Migr

D.

You conduct a series of Compliance Assessments to check that thearchitecture is being implemented as required by the contract. This is donenow to confirm that the implementation team is following the correctdevelopment process, and if not, so course correction is viable. This involvesusing monitoring tools and making sure that performance targets are beingachieved. If the targets are not met, you would then need to make adjustmentsto the pe

Question # 4

Please read this scenario prior to answering the question

You are employed as an Enterprise Architect in a team at a large company. The

company sells luxury food and drinks in more than 10,000 stores worldwide. The

company is a leader in using technology to connect with its customers. This includes

online ordering, mobile apps, and rewards programs. The company is also famous for

bringing new ideas to the market, like ordering through apps, using Al to suggest

personalized options, self-service pickup stations, and changing prices based on

demand.

The stores are open every day. They send timely sales data to a central system that

manages inventory. This system can predict what products are needed, adjust how

much stock there is, and order more stock automatically. The stores and the main

inventory system work directly with the mobile apps, allowing orders to be made

online. The central inventory system is located at the company ' s main data center.

The company will merge with a major competitor. This competitor has a synergistic

business. Leaders from both companies have told shareholders that the merger will

happen fast. There will be minimal impact for customers. All stores will keep the

current brand names. They will combine their systems, choosing the best ones to use.

This means their store management and back-office systems will become one. They

will stop using duplicate systems and use one main system to manage the stores.

They will also cut down on the number of back-office applications they use.

The Request for Architecture Work to oversee the merger has been approved.

Stakeholders, concerns, and business requirements have been identified. The

stakeholders have made it clear that they expect to continue to be able to innovate

quickly, and that changes should not restrict that capability. The scope of what is

inside and what is outside the architecture efforts has been confirmed. The next step

is to revisit and review the Architecture Principles, as they form part of the constraints

on architecture work.

Business Continuity is essential given that the business depends on real-time

ordering and automated inventory management. During the systems integration,

maintaining service for customers and inventory operations must be prioritized

Refer to the scenario

You have been asked to identify the most relevant Architecture Principles for the

merger besides Business Continuity.

Based on the TOGAF standard, which of the following is the best answer?

[Note: You should assume that the company follows the example set of Architecture

Principles provided in the TOGAF standard, ADM Techniques, Architecture Principles

chapter.]

A.

Control Technical Diversity will help by standardizing technology platforms aspart of the integration process. This will be vital for standardizing the appintegration for digital orders with the back-office systems, and will reducecomplexity and costs during integration. Data Trustee will establish owners tomanage the shared data across the company, thereby assuring data quality.Ease-of-Use is needed to make sure that new user interfaces fo

B.

Primacy of Principles will make sure that the same principles apply to bothorganizations of the newly merged operation, creating consistency acrosslocations. Data as an Asset is critical. Since you ' re maintaining separate mobileapps but consolidating back-end systems, treating data as an asset becomesessential. This principle helps ensure that customer data, and inventoryinformation from both brands are properly integrated and managed.Tec

C.

Compliance with the Law makes sure that all company activities comply withrelevant laws and regulations. This principle provides the foundation forensuring the merger meets all legal requirements. Requirements-BasedChange will make sure that when combining systems, changes to applicationsand technology are only made if required by business needs. ResponsiveChange Management focuses on the speed needed to achieve the goals setby the leaders

D.

Service orientation will speed up the merger and make it easier to integratesystems while maintaining business operations. Maximize Benefit to theEnterprise will make sure that merger decisions prioritize the overall benefit tothe combined company. Common Use Applications across the mergedcompany is preferred over the use of similar or duplicative applications forcertain parts of the company. This help supports the goal of merging back-offi

Question # 5

You are employed as an Enterprise Architect within an Enterprise Architecture (EA) team at an environmental agency. The agency has multiple divisions, and is responsible for overseeing environmental protection, regulation, and conservation efforts.

The agency has a well-established EA practice and follows the TOGAF standard as its method for architecture development. Along with the EA program, the agency also uses various management frameworks, including business planning, project/portfolio management, and operations management. The EA program is sponsored by the Chief Information Officer (CIO), who has actively promoted architecting with agility within the EA department as the preferred approach for projects.

The agency is preparing itself for a world where Artificial Intelligence (Al) is widely adopted. As a result, the agency is looking to determine the impact and role that Al will play moving forward.

The CIO has approved a Request for Architecture Work to look at how Al can be used for services across the agency. She has noted that digital platforms will be a priority for investment in order to scale the planned Al applications. Using Al to automate tasks and make things run smoother is seen as a big advantage. Process automation, and improved efficiency from manual, repetitive activities has been identified as the key benefits of applying generative Al to their agency ' s business. This will include back-office automation, for example, for help center agents who receive hundreds of email enquiries. This should also improve services for their customers by making them more efficient and personalized, tailored to each individual’s needs.

Many of the agency leaders are worried about relying too much on Al. Some leaders think their employees will need to learn new skills. Some employees are worried they might lose their jobs to Al. Other leaders worry about security and cyber resilience in the digital platforms needed for Al to be successful.

Refer to the scenario

The EA team leader has asked how to address the concerns, and how to manage the risks of a new architecture for the project.

Based on the TOGAF standard which of the following is the best answer?

A.

You recommend creating an Organization Map to display the links between different parts of the agency. This will help the EA team to find and involve all areas of the agency impacted by this strategic change. Multiple business models should then be created that can be applied to Al related projects. A meeting will be held with the stakeholders to teach them how to interpret the models and see how their concerns are being addressed. Risk wil

B.

You recommend conducting an analysis that separates the different types of stakeholders into groups. They can be put into categories including corporate functions, end-user organization, project organization, systems, and external. Models should be developed for each stakeholder category to ensure that that all the necessary information and details are considered. A meeting should be held with the stakeholders to verify that their concerns

C.

You recommend that the key stakeholders be formally identified. This should include those who will be most helpful for the change to be successful. A Communication Plan should be made to address their needs. This plan should include a report that summarizes the key features of the architecture based on stakeholder requirements and addressing concerns. You meet with each key stakeholder to make sure their concerns are being addressed. You ma

D.

You recommend an assessment of the power, influence, and interest of key individuals affected by the project. This includes documenting the positions, concerns, issues, and cultural factors of each interest group. This information will shape how the architecture is presented and explained. The concerns and relevant views can be defined for each group and recorded in the Architecture Vision document. The requirements for addressing risk shou

Question # 6

Please read this scenario prior to answering the question

You are working as Chief Enterprise Architect at a large Internet company. The company has many divisions, ranging from cloud to logistics. The company has grown rapidly, expanding from initially selling physical books and media to a range of services including an online marketplace, live-streaming. eBooks. and cloud services.

Overall management of the numerous divisions has become challenging. Recent high-profile projects have overrun on budget and under delivered, damaging the company ' s reputation, and adversely impacting its share price. There is a widely held view within the executive management that the organization structure has played a major role in these project failures.

The company has an established Enterprise Architecture program based on the TOGAF standard, sponsored jointly by the Chief Executive Officer (CEO) and Chief Information Officer (CIO). The CEO has decided that the company needs to reorganize its divisions around artificial intelligence and machine learning with a focus on automation. The CEO has worked with the Enterprise Architects to create a strategic architecture for the reorganization, including an Architecture Vision, together with definitions for the four domain architectures. This sets out an ambitious vision of the future of the company over a three-year period. This includes a set of work packages and includes three distinct transformations.

The CIO has made it clear that prior to the approval of the detailed Implementation and Migration plan, the EAteam will need to assess the risks associated with the proposed architecture. He has received concerns from key stakeholders across the company that the proposed reorganization may be too ambitious and there is doubt whether it can produce sufficient value to warrant the risks.

Refer to the scenario

You have been asked to recommend an approach to satisfy these concerns. Based on the TOGAF Standard, which of the following is the best answer?

A.

The Enterprise Architects should evaluate the organization ' s readiness to undergo change. This will allow the risks associated with the transformations to be identified, classified, and mitigated for. This should include identifying dependencies between the set of changes, including gaps and work packages. It will also identify improvement actions to be worked into the Implementation and Migration Plan. The business value, effort, and ris

B.

The Enterprise Architects should bring together information about potential approaches and produce several alternative target transition architectures. They should then investigate the different architecture alternatives and discuss these with stakeholders using the Architecture Alternatives and Trade-offs technique. Once the target architecture has been selected, it should be analyzed using a state evolution table to determine the Transit

C.

Establishing interoperability in alignment with the corporate operating model will ensure risks are minimized. The Enterprise Architects should apply an interoperability analysis to evaluate any potential issues across the architecture. This should include the development of a matrix showing the interoperability requirements. These can then be included within the transformation strategy embedded in the target transition architectures. The E

D.

Before preparing the detailed Implementation and Migration plan, the EnterpriseArchitects should review and consolidate the gap analysis results from Phases B toThis will identify the transformations required to achieve the proposed TargetArchitecture. The Enterprise Architects should then assess the readiness of theorganization to undergo change and determine an overall direction to address andmitigate risks identified. The Transition Arch

Question # 7

Scenario

Your role is that of an Enterprise Architect, reporting to the Chief Enterprise Architect, at a technology company.

The company uses the TOGAF standard as the method and guiding framework for its Enterprise Architecture (EA) practice. The Chief Technology Officer (CTO) is the sponsor of the activity. The EA practice uses an iterative approach for its architecture development. This has enabled the decision-makers to gain valuable insights into the different aspects of the business.

The nature of the business is such that the data and the information stored on the company systems is the company’s major asset and is highly confidential. The company employees travel a lot for work and need to communicate over public infrastructure. They use message encryption, secure internet connections using Virtual Private Networks (VPNs), and other standard security measures. The company has provided computer security awareness training for all its staff. However, despite good education and system security, there is still a need to rely on third-party suppliers for infrastructure and software.

The Chief Security Officer (CSO) has noted an increase in ransomware (malicious software used in ransom demands) attacks on companies with a similar profile. The CSO recognizes that no matter how much is spent on education and support, the company could be a victim of a significant attack that could completely lock them out of their important data.

A risk assessment has been completed, and the company has looked for cyber insurance that covers ransomware. The price for this insurance is very high. The CTO recently saw a survey that said 1 out of 4 businesses that paid ransoms could not get their data back, and almost thesame number were able to recover the data without paying. The CTO has decided not to get cyber insurance to cover ransom payment.

You have been asked to describe the steps you would take to strengthen the current architecture to improve data protection.

Based on the TOGAF standard, which of the following is the best answer?

A.

You would ensure that the company has in place up-to-date processes for managing change to the current Enterprise Architecture. Based on the scope of the concerns raised, you recommend that this be managed at the infrastructure level. Changes should be made to the baseline description of the Technology Architecture. The changes should be approved by the Architecture Board and implemented by change management techniques.

B.

You would request an Architecture Compliance Review with the scope to examine the company’s ability to respond to ransomware attacks. You would identify the departments involved and have them nominate representatives. You would then tailor checklists to address the requirement for increased resilience. You would circulate to the nominated representatives for them to complete. You would then review the completed checklists, identifying and r

C.

You would monitor for technology updates from your existing suppliers that could enhance the company’s capabilities to detect, react, and recover from an IT security incident. You would prepare and run a disaster recovery planning exercise for a ransomware attack and analyze the performance of the current Enterprise Architecture. Using the findings, you would prepare a gap analysis of the current Enterprise Architecture. You would prepare c

D.

You would assess business continuity requirements and analyze the current Enterprise Architecture for gaps. You would recommend changes to address the situation and create a change request. You would engage the Architecture Board to assess and approve the change request. Once approved, you would create a new Request for Architecture Work to begin an ADM cycle to implement the changes.

Question # 8

Please read this scenario prior to answering the question

You are employed as an Enterprise Architect within a large law firm. The firm operates in many countries and has a complicated structure. Every office must follow the local regulations in their country.

The firm has an established Enterprise Architecture (EA) department which has been operating for several years. It has architecture governance and development processes based on the TOGAF standard. In addition to the EA program, the firm has several management frameworks in use, including business planning, project/portfolio management, and operations management. The Architecture Board includes representatives from all parts of the firm.

The Chief Information Officer (CIO) is the sponsor of the Enterprise Architecture program. The CIO has actively encouraged architecting with agility within the EA department as her preferred approach for projects.

The CIO has given approval for a Request for Architecture Work to explore the adoption of an Al-based system for managing legal cases and financial processes.

Senior management has become more and more worried about how well the business is running, especially with the advancements In Artificial Intelligence (Al). Many of the firm ' s competitors have started using Al to assist with legal strategies, streamline processes, and boost productivity. One of the most important benefits Al has for the business is its ability to increase accuracy and minimize mistakes.

Some of the top managers are worried about a change in the way of working, and if it will achieve the goals. Their staff also fear that management will use the system to measure their performance. The CIO wants to know how to address these concerns and reduce risks. The new system would provide guidance to legal professionals and analysts on which tasks to focus on. The main goals are to improve productivity and make better use of staff. In addition, the CIO hopes these changes will lead to higher customer satisfaction.

Refer to the scenario

The Chief Information Officer (CIO) has asked you how to address the concerns and lower risks when introducing artificial intelligence (Al) in the firm.

Based on the TOGAF standard which of the following is the best answer?

A.

The stakeholders should be identified, and their concerns documented in the Architecture Vision. A Communications Plan should be created to address the stakeholders. This plan should include a report that summarizes the key features of the architecture with respect to each location and the stakeholders* requirements. You will check with key stakeholders that their concerns are being addressed. Risk mitigation should be addressed as part of

B.

Models should be created for each of the high-level Business. Application and Technology architectures included in the Architecture Vision. The models can be used to help the top management understand the new business direction, and make sure that the system will be compliant with the local regula tions for each operating entity. A formal review should be held with the stakeholders to confirm that their concerns have been properly addressed

C.

A set of business models should be developed with focus on the essential business problem and the vision of the change being proposed. These models will be used to build consensus with the top managers on the approach for deployment of the Al-based solution. A meeting should be held with the key stakeholders to explain how to use and understand the models. Risk will be managed as part of the Security Architecture development.

D.

An analysis of the stakeholders should be carried out. This will allow the architects to define groups of stakeholders who have common concerns and include development of a Stakeholder Map. The concerns and relevant views should then be defined for each group and recorded in the Architecture Vision document. To reduce risk, you include a requirement that there be progressive development of the target architecture to get regular feedback.

Question # 9

Please read this scenario prior to answering the question

You are employed as an Enterprise Architect at a large technology company with diverse business lines. The company has multiple divisions, engaged in mobile, e-commerce, cloud computing services, and a social network.

The company has an established Enterprise Architecture (EA) practice based on the TOGAF standard, including the TOGAF ADM. The EA program is sponsored by the Chief Information Officer (CIO). The use of EA has enabled the company to gain valuable insights into different parts of the business. One of the primary goals in the EA program charter is to coordinate efforts between the teams in each division. This has made sure that the mobile, e-commerce, cloud, and social media initiatives remain aligned with business strategy.

The practice has an established Architecture Capability and uses iteration for architecture development. The iterative approach is well-suited for modern digital transformation initiatives, where the company must adapt quickly to new business and market challenges. In addition to the EA program, the company uses several management frameworks, including business planning, project/portfolio management, and operations management.

The company is growing rapidly. A consequence of this rapid growth has been the proliferation of multiple IT solutions, with architecture giving way to growth. The company appears to be failing to architect its growth. Several systems have proved unreliable with some major outages, including the e-commerce system being offline for eight hours at the start of the holiday sales period, as well as the cloud computing services outage, which took down several popular websites. The service management organization within the company has blamed the outages on misalignment of the IT solutions.

The Governing Board has raised concerns about the outages. As a consequence, the CEO has asked for better reporting and management of the IT portfolio. The task has been assigned to the EAteam, with a constraint to maintain business as usual.

Refer to the Scenario

You have been asked to assess the IT solutions to determine where problems are occurring and where change is needed.

Based on the TOGAF standard, which of the following is the best answer?

A.

The team should start an iteration cycle by defining the baseline Technology Architecture first to assess the current infrastructure capacity and capability for the company. There should be an assessment of the operational performance data. This is needed to diagnose the causes of the system outages. The results of the assessment can then be used to identify the required changes to make sure that the misalignments between solutions are rem

B.

The team should start an iteration cycle of target architecture definition. The team will then identify the requirements, drivers, issues, and constraints to support the change. The result will be a more resilient architecture to support definition of a set of IT solutions that will address the misalignment. You would ensure that non-functional requirements are well defined to make sure that the target architecture is robust and reliable.

C.

The team should commence an architecture development cycle through the architecture definition phases (B-D) with the purpose to understand the causes of the outages. This will allow the concerns of the Governing Board to be addressed through each of the Business, Information Systems, and Technology Architecture phases. This will identify the changes in a structured manner and make sure they address the requirements.

D.

The team should evaluate the IT resources across the company against the operational performance data and business needs. This will include a review of availability and responsiveness. You would assess the current applications and technology infrastructure by commencing an iteration cycle following a baseline first architecture development approach. This would allow you to identify improvement opportunities and allow you to determine where

Question # 10

Please read this scenario prior to answering the question

You are employed as an Enterprise Architect at a technology company, reporting directly

to the Chief Enterprise Architect. The company supplies personnel and delivers cloud-

based solutions to numerous government agencies.

The nature of the business is such that the data and the information stored on the

company systems is the company ' s major asset and is highly confidential. The company

employees work remotely and need constant access to the company systems, which is

done by the public infrastructure. They use message encryption, secure internet

connections using Virtual Private Networks (VPNs), and other standard security

measures. The company provides computer security awareness training for all its staff.

The Chief Security Officer (CSO) has noted an increase in distributed denial of service

(DDoS) attacks on companies with a similar profile. The CSO understands that even

with thorough preparation, a major attack could stop employees from being able to do

their jobs. This could lead to a large financial loss, damage to the company ' s reputation

with customers, and employees being unable to work.

A risk assessment has been completed and the company has looked for cyber insurance

that covers such attacks. The price for this insurance is very high. The CTO has decided

not to get cyber insurance to cover such attacks.

The company follows the TOGAF standard as the method and guiding framework for its

Enterprise Architecture (EA) practice. The Chief Technology Officer (CTO) is the sponsor

of the activity. The practice uses an iterative approach for its architecture development.

This has enabled the decision makers to gain valuable insights into the different aspects

of the business

Please read this scenario prior to answering the question

You have been asked to describe the steps you would take to strengthen the current

architecture to improve data protection.

Based on the TOGAF standard which of the following is the best answer?

A.

You would request technology updates from existing suppliers that improve thecompany ' s capabilities to detect, react, and recover from an incident. Youwould run a simulated ransomware attack to evaluate the current EnterpriseArchitecture ' s resilience and recovery capabilities. Using the findings, youwould perform a gap analysis of the current Enterprise Architecture, andprepare change requests to address identified gaps. You would docum

B.

You would run a planning exercise to assess the business continuityrequirements and analyze the current Enterprise Architecture for gaps. Youcreate a formal change request related to business resilience and maintainingcritical business functions. You would arrange a meeting of the ArchitectureBoard to assess and approve the change request. Once approved you wouldcreate a new Request for Architecture Work to begin an ADM cycle toimplement th

C.

You would ensure that business value and cost of continuity measures areunderstood by key stakeholders, and that the company has in place up-to-dateprocesses for managing change to the current Enterprise Architecture. Yourecommend that DDoS mitigation be addressed at the infrastructure level toensure effective, scalable protection. Changes should be made to the baselinedescription of the Technology Architecture. The changes should be approv

D.

You would hold an Architecture Compliance Review with the scope to examinethe company ' s ability to respond to such attacks. You would identify thedepartments involved and have them nominate representatives. You wouldthen tailor checklists to address the requirement for increased businesscontinuity and resilience. You would circulate the checklists to the nominatedrepresentatives for them to complete. You would review the completedchecklis

Go to page: