The Open Group · TOGAF-RS
This credential validates an individual's understanding of essential security and risk concepts in relation to the TOGAF® Architecture Development Method (ADM), including Enterprise Risk Management (ERM), Information Security Management (ISM), and Enterprise Security Architecture (ESA). It demonstrates knowledge of how IT security and risk standards such as ISO/IEC 27000, ISO 31000, and COBIT relate to the TOGAF standard.
Practice Questions
600
≈ 10 practice exams
Duration
180 minutes
Passing Score
Pass/Fail
Difficulty
FoundationalLast Updated
Jun 2026
Use this TOGAF-RS practice exam to prepare for The Open Group Certified: Integrating Risk and Security within a TOGAF® Enterprise Architecture with realistic questions, detailed explanations, and focused study modes. The practice bank includes 600 questions for The Open Group TOGAF-RS, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to recurring topics such as Security and Risk Concepts in TOGAF ADM, Enterprise Security Architecture (ESA), Enterprise Risk Management (ERM), Information Security Management (ISM), and IT Security and Risk Standards (ISO/IEC 27000, ISO 31000, COBIT). Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The Open Group Certified: Integrating Risk and Security within a TOGAF® Enterprise Architecture is an awareness-level credential that validates foundational knowledge of how security and risk management integrate with the TOGAF® Architecture Development Method (ADM). It demonstrates that the holder understands the essential concepts of Enterprise Security Architecture (ESA), Enterprise Risk Management (ERM), and Information Security Management (ISM), and knows how these disciplines relate to each phase and artifact of the TOGAF ADM. The credential is part of the broader TOGAF Certification Portfolio built upon the TOGAF Standard, 10th Edition, and is designed to establish a common language between Security Architects and Enterprise Architects when developing risk-aware enterprise architectures.
The certification also covers how major IT security and risk standards — specifically the ISO/IEC 27000 family of standards, ISO 31000, and COBIT® — relate to and complement the TOGAF standard. Candidates learn why security and risk management must be treated as cross-cutting concerns that span the entire enterprise architecture lifecycle rather than being addressed in isolated phases. The credential is structured as a compact learning credential requiring approximately three hours of study, making it accessible as a standalone qualification or as a complement to broader TOGAF Enterprise Architecture certifications.
This credential is designed for professionals who need a structured, foundational understanding of security and risk concepts in the context of enterprise architecture. Primary audiences include Enterprise Architects who want to incorporate security and risk practices into their TOGAF ADM work, Security Architects seeking to align their practice with enterprise architecture frameworks, and IT risk and compliance professionals who collaborate with architecture teams. It is equally relevant for individuals working with governance frameworks such as COBIT or standards like ISO/IEC 27001 and ISO 31000 who need to understand how these standards interact with the TOGAF methodology.
Because the credential is at the awareness level with no prerequisites, it is well-suited to those who are early in their enterprise architecture or security architecture careers, as well as experienced practitioners expanding their knowledge into adjacent disciplines. Program managers, IT auditors, and CISOs who need to communicate with architecture teams or evaluate security architecture outputs will also find the credential valuable.
There are no formal prerequisites to sit for this credential. Candidates are not required to hold any prior TOGAF certification, though familiarity with the basic concepts of the TOGAF ADM — such as the architecture phases (Preliminary through Architecture Change Management) and core TOGAF terminology — will help candidates contextualize the security and risk content more effectively. No prior security certifications are required.
In practice, candidates will benefit from some exposure to enterprise IT environments and a general awareness of IT governance concepts. Those with experience in security operations, IT risk management, or enterprise architecture will find the material more immediately applicable. The Open Group offers a self-study option through its learning management system for candidates who wish to build prerequisite TOGAF knowledge before attempting this credential.
The assessment for this credential is delivered either through an Accredited Training Course (ATC) provider — in which case the assessment format is at the provider's discretion — or through The Open Group's own self-study online learning option, which includes a built-in assessment. The self-study path is available through The Open Group's online shop and learning management system. The credential requires a minimum of three hours of learning to be completed before the assessment is attempted. The Open Group awards a digital Open Badge via Credly and a certificate upon successful completion.
Where scenario-based questions are used, as is common across the TOGAF Certification Portfolio, each question presents a real-world scenario with four possible answers ranked from best to worst. Under this model, the best answer earns 5 points, the second-best 3 points, the third-best 1 point, and the worst answer 0 points. Specific details such as the total number of questions and a published numeric passing score are not publicly disclosed by The Open Group for this credential; candidates should confirm the precise assessment parameters with their chosen training provider or The Open Group's official exam portal. The overall credential is classified as a pass/fail award.
Earning this credential signals to employers that an architect or security professional understands how to embed risk and security thinking into enterprise architecture work from the outset, rather than treating them as compliance afterthoughts. It is particularly valued in organizations that have adopted TOGAF as their architecture framework and are seeking to align security governance with frameworks like ISO/IEC 27001 or COBIT. Roles that benefit directly from this credential include Enterprise Architect, Security Architect, IT Risk Manager, IT Governance Analyst, and Information Security Manager. Because it is an awareness-level credential, it is often pursued alongside or as preparation for higher-level TOGAF certifications rather than as a standalone career milestone.
The credential carries one point in The Open Group's TOGAF Certification Portfolio, contributing to broader TOGAF professional recognition. While salary data specific to this credential is not published, professionals who combine TOGAF certification with security and risk specialization are well positioned for senior architecture and governance roles. Industry demand for architects who can speak fluently across security, risk, and enterprise architecture continues to grow, particularly in regulated sectors such as financial services, healthcare, and government, where risk-aware architecture is a compliance requirement.
5 sample questions with answers and explanations. The full bank has 600 questions, enough for 10 full-length practice exams.
Preview — answers shown1. The enterprise architecture team at Relecloud Telecommunications is reviewing how G152 positions security in relation to The Open Group's Boundaryless Information Flow™ vision. A debate has arisen between team members who argue security should maximize restriction by default and those who advocate an enabling approach. Which position does G152 support? (Select one!)
Explanation
G152 explicitly supports The Open Group's vision of Boundaryless Information Flow™ by positioning security as an enabler rather than an inhibitor of appropriate information sharing across organizational, geographic, and system boundaries. Security controls, according to G152, should be proportionate to risk, aligned with business requirements, implemented consistently across boundaries, and transparent in their operation. This philosophy rejects the notion that maximum restriction equates to maximum security. Instead, G152 advocates for risk-proportionate controls that facilitate legitimate information flows while maintaining appropriate protection levels. Security that obstructs information flow fails to serve business objectives and undermines the enterprise architecture program's purpose. This enabling perspective is directly connected to the cross-cutting nature of security described throughout G152, where security is integrated into every phase to support rather than constrain business outcomes.
2. A quantitative risk analyst at Fabrikam Technology is applying Open FAIR methodology to assess the risk of a targeted phishing attack against the finance department. The analyst determines that threat agents are expected to attempt phishing attacks 20 times per year (Threat Event Frequency = 20). Based on historical data and current security controls, the probability that any given phishing attempt successfully results in a loss event is 15%. What is the Loss Event Frequency (LEF) for this risk scenario? (Select one!)
Explanation
In Open FAIR, Loss Event Frequency is calculated as Threat Event Frequency multiplied by Vulnerability, where Vulnerability is the probability that a threat event becomes a loss event expressed as a value between 0 and 100%. LEF = TEF x Vulnerability = 20 x 0.15 = 3 loss events per year. The value of 15 confuses the Vulnerability percentage with an absolute count of events rather than applying it as a multiplier. The value of 20 equals the Threat Event Frequency itself, which is the frequency of attempts, not successful loss events. The value of 133 results from incorrectly dividing TEF by Vulnerability rather than multiplying. Open FAIR defines Vulnerability specifically as susceptibility — the conditional probability of a loss event given a threat event — which is conceptually distinct from the traditional security meaning of a technical system weakness.
3. A digital banking platform is implementing security controls for its electronic funds transfer system. The security team identifies two specific requirements: the system must verify that each transaction was genuinely initiated by the claimed customer, and customers must be unable to later deny having authorized a completed transfer. Which pair of extended information security properties directly address these two requirements? (Select two!)
Multiple correct answersExplanation
Authenticity is the extended security property ensuring that the identity of a data originator or system actor can be verified as legitimate. It directly addresses the requirement to confirm that a transaction was genuinely initiated by the claimed customer. Non-repudiation is the extended security property providing accountability by ensuring a party cannot later deny a prior action or commitment. It directly addresses the requirement that customers cannot repudiate an authorized transfer after the fact. Confidentiality protects data from unauthorized disclosure but does not verify originator identity or prevent denial of prior actions. Availability ensures systems remain accessible to authorized users but is unrelated to transaction attribution or repudiation prevention. Integrity ensures data has not been altered in transit but does not prevent a customer from falsely claiming they never initiated a transaction.
4. Tailspin Aerospace is deploying a new collaborative design platform to share engineering specifications with external manufacturing partners and regulatory certification bodies across multiple countries. A programme manager argues that implementing security controls on the inter-organisational data channels will obstruct information flow, reduce partner collaboration efficiency, and delay regulatory submissions. He proposes minimising security requirements for external data exchanges. Which statement most accurately reflects G152's guidance on this scenario? (Select one!)
Explanation
G152 directly supports The Open Group's vision of Boundaryless Information Flow, which calls for information to move securely across organisational and geographic boundaries without unnecessary obstruction. G152 explicitly states that security should enable rather than inhibit information flow, with controls that are proportionate to risk, aligned with business requirements, implemented consistently across boundaries, and transparent in their operation. Appropriately designed security controls make trusted cross-boundary collaboration possible by establishing the assurance required for partners and regulators to exchange sensitive data. The premise that security inherently conflicts with information flow is contradicted by G152's guidance. Deferring security considerations until after architecture design is finalised is contrary to G152's position that security must be integrated from the outset of every architecture development effort.
5. A senior IT auditor at Contoso Financial is reviewing the accountability structure of the organization's COBIT 5 implementation. The audit committee wants to understand how COBIT 5 assigns responsibility for IT governance compared to IT management, and which process domains belong to each. Which statement accurately describes the COBIT 5 accountability structure? (Select one!)
Explanation
COBIT 5 draws a deliberate and fundamental distinction between governance and management as one of its five core principles. Governance processes reside exclusively in the EDM domain, which stands for Evaluate, Direct, and Monitor. The five EDM processes are the responsibility of the board of directors and senior executives, who set direction and monitor performance against stakeholder needs. The remaining 32 management processes are distributed across the APO (Align, Plan, and Organise), BAI (Build, Acquire, and Implement), DSS (Deliver, Service, and Support), and MEA (Monitor, Evaluate, and Assess) domains, for a total of 37 processes. These management processes are the accountability of executive management. Treating governance and management as interchangeable misrepresents the core accountability boundaries COBIT 5 is designed to clarify. Placing management processes in the EDM domain and governance processes in the other four domains inverts the actual domain structure entirely. Distributing both types evenly across all domains contradicts the deliberate separation that defines COBIT 5 governance design.
TOGAF® Business Architecture Foundation (OGBA-101)
OGBA-101 · 600 questions
TOGAF® Enterprise Architecture Foundation (OGEA-101)
OGEA-101 · 600 questions
TOGAF® Enterprise Architecture Part 2 Exam (OGEA-102)
OGEA-102 · 600 questions
TOGAF® Enterprise Architecture Leader
TOGAF EA Leader · 598 questions
TOGAF® Framework Digital Specialist
OG0-DS1 · 598 questions
The Open Group Certified: TOGAF® Framework Agile Specialist
TOGAF-Agile-Specialist · 589 questions
$17.99
One-time access to this exam