The Open Group · TOGAF-RS
This credential validates an individual's understanding of essential security and risk concepts in relation to the TOGAF® Architecture Development Method (ADM), including Enterprise Risk Management (ERM), Information Security Management (ISM), and Enterprise Security Architecture (ESA). It demonstrates knowledge of how IT security and risk standards such as ISO/IEC 27000, ISO 31000, and COBIT relate to the TOGAF standard.
Practice Questions
600
≈ 10 practice exams
Duration
180 minutes
Passing Score
Pass/Fail
Difficulty
FoundationalLast Updated
Jun 2026
Use this TOGAF-RS practice exam to prepare for The Open Group Certified: Integrating Risk and Security within a TOGAF® Enterprise Architecture with realistic questions, detailed explanations, and focused study modes. The practice bank includes 600 questions for The Open Group TOGAF-RS, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to recurring topics such as Security and Risk Concepts in TOGAF ADM, Enterprise Security Architecture (ESA), Enterprise Risk Management (ERM), Information Security Management (ISM), and IT Security and Risk Standards (ISO/IEC 27000, ISO 31000, COBIT). Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The Open Group Certified: Integrating Risk and Security within a TOGAF® Enterprise Architecture is an awareness-level credential that validates foundational knowledge of how security and risk management integrate with the TOGAF® Architecture Development Method (ADM). It demonstrates that the holder understands the essential concepts of Enterprise Security Architecture (ESA), Enterprise Risk Management (ERM), and Information Security Management (ISM), and knows how these disciplines relate to each phase and artifact of the TOGAF ADM. The credential is part of the broader TOGAF Certification Portfolio built upon the TOGAF Standard, 10th Edition, and is designed to establish a common language between Security Architects and Enterprise Architects when developing risk-aware enterprise architectures.
The certification also covers how major IT security and risk standards — specifically the ISO/IEC 27000 family of standards, ISO 31000, and COBIT® — relate to and complement the TOGAF standard. Candidates learn why security and risk management must be treated as cross-cutting concerns that span the entire enterprise architecture lifecycle rather than being addressed in isolated phases. The credential is structured as a compact learning credential requiring approximately three hours of study, making it accessible as a standalone qualification or as a complement to broader TOGAF Enterprise Architecture certifications.
This credential is designed for professionals who need a structured, foundational understanding of security and risk concepts in the context of enterprise architecture. Primary audiences include Enterprise Architects who want to incorporate security and risk practices into their TOGAF ADM work, Security Architects seeking to align their practice with enterprise architecture frameworks, and IT risk and compliance professionals who collaborate with architecture teams. It is equally relevant for individuals working with governance frameworks such as COBIT or standards like ISO/IEC 27001 and ISO 31000 who need to understand how these standards interact with the TOGAF methodology.
Because the credential is at the awareness level with no prerequisites, it is well-suited to those who are early in their enterprise architecture or security architecture careers, as well as experienced practitioners expanding their knowledge into adjacent disciplines. Program managers, IT auditors, and CISOs who need to communicate with architecture teams or evaluate security architecture outputs will also find the credential valuable.
There are no formal prerequisites to sit for this credential. Candidates are not required to hold any prior TOGAF certification, though familiarity with the basic concepts of the TOGAF ADM — such as the architecture phases (Preliminary through Architecture Change Management) and core TOGAF terminology — will help candidates contextualize the security and risk content more effectively. No prior security certifications are required.
In practice, candidates will benefit from some exposure to enterprise IT environments and a general awareness of IT governance concepts. Those with experience in security operations, IT risk management, or enterprise architecture will find the material more immediately applicable. The Open Group offers a self-study option through its learning management system for candidates who wish to build prerequisite TOGAF knowledge before attempting this credential.
The assessment for this credential is delivered either through an Accredited Training Course (ATC) provider — in which case the assessment format is at the provider's discretion — or through The Open Group's own self-study online learning option, which includes a built-in assessment. The self-study path is available through The Open Group's online shop and learning management system. The credential requires a minimum of three hours of learning to be completed before the assessment is attempted. The Open Group awards a digital Open Badge via Credly and a certificate upon successful completion.
Where scenario-based questions are used, as is common across the TOGAF Certification Portfolio, each question presents a real-world scenario with four possible answers ranked from best to worst. Under this model, the best answer earns 5 points, the second-best 3 points, the third-best 1 point, and the worst answer 0 points. Specific details such as the total number of questions and a published numeric passing score are not publicly disclosed by The Open Group for this credential; candidates should confirm the precise assessment parameters with their chosen training provider or The Open Group's official exam portal. The overall credential is classified as a pass/fail award.
Earning this credential signals to employers that an architect or security professional understands how to embed risk and security thinking into enterprise architecture work from the outset, rather than treating them as compliance afterthoughts. It is particularly valued in organizations that have adopted TOGAF as their architecture framework and are seeking to align security governance with frameworks like ISO/IEC 27001 or COBIT. Roles that benefit directly from this credential include Enterprise Architect, Security Architect, IT Risk Manager, IT Governance Analyst, and Information Security Manager. Because it is an awareness-level credential, it is often pursued alongside or as preparation for higher-level TOGAF certifications rather than as a standalone career milestone.
The credential carries one point in The Open Group's TOGAF Certification Portfolio, contributing to broader TOGAF professional recognition. While salary data specific to this credential is not published, professionals who combine TOGAF certification with security and risk specialization are well positioned for senior architecture and governance roles. Industry demand for architects who can speak fluently across security, risk, and enterprise architecture continues to grow, particularly in regulated sectors such as financial services, healthcare, and government, where risk-aware architecture is a compliance requirement.
5 sample questions with answers and explanations. The full bank has 600 questions, enough for 10 full-length practice exams.
Preview — answers shown1. A senior IT governance consultant at Fabrikam Utilities is briefing the board of directors on the COBIT 5 framework. She explains that COBIT 5 makes a fundamental distinction between governance activities performed at the board level and management activities executed by IT leadership. The board asks her to identify which process domain belongs exclusively to the governance tier in COBIT 5. Which domain represents governance rather than management in COBIT 5? (Select one!)
Explanation
In COBIT 5, the governance tier contains only the EDM (Evaluate, Direct, Monitor) domain with 5 processes. Governance is board-level work: evaluating stakeholder needs, directing strategy, and monitoring performance and compliance. The management tier contains four domains — APO (Align, Plan, Organize with 13 processes), BAI (Build, Acquire, Implement with 10 processes), DSS (Deliver, Service, Support with 6 processes), and MEA (Monitor, Evaluate, Assess with 3 processes) — totaling 32 management processes. The governance-management separation is fundamental to COBIT 5 because board members are accountable for governance objectives while IT leadership is accountable for management outcomes. APO, BAI, and DSS are all management domains, not governance domains.
2. Woodgrove Bank is implementing a new lending platform with complex, dynamic access requirements: branch managers need access only during local business hours, compliance officers require read-only access when connecting from the corporate headquarters network, and loan officers' permitted actions should automatically expand during active customer appointment sessions. Standard role assignments have proven insufficient to enforce these constraints. Which access control model should the security architect recommend? (Select one!)
Explanation
Attribute-Based Access Control is designed precisely for complex, context-sensitive access scenarios where decisions depend on multiple simultaneous conditions evaluated at the time of each request. It combines user attributes such as role and department, resource attributes such as sensitivity classification, environmental attributes such as time of day and network location, and action attributes such as read versus approve. The branch manager's time-based restriction, the compliance officer's network location constraint, and the loan officer's session-context expansion are all attribute-driven conditions that Attribute-Based Access Control handles natively and dynamically without requiring manual role reassignment. Role-Based Access Control assigns static permissions at provisioning time and cannot natively enforce time-of-day or session-context variations without complex compensating controls that undermine manageability. Mandatory Access Control is a rigid classification-based model designed for government and military environments with formal clearance hierarchies and is unsuitable for a commercial bank's dynamic operational requirements. Discretionary Access Control delegates permission decisions to individual resource owners, creating dangerous inconsistency and unmanageable administrative overhead at enterprise scale.
3. Contoso Healthcare is deploying a new clinical information system and the security team must design an authentication mechanism that satisfies the definition of multi-factor authentication. The team evaluates four proposed authentication configurations to identify which qualifies as genuine MFA. Which authentication configuration correctly qualifies as genuine multi-factor authentication? (Select one!)
Explanation
Multi-factor authentication requires presenting credentials from at least two different authentication factor categories. The recognized categories are: something you know (knowledge factors such as passwords, PINs, and security questions), something you have (possession factors such as hardware tokens and smart cards), and something you are (biometric factors such as fingerprints, facial recognition, and iris scans). Combining a password with a fingerprint scan combines a knowledge factor with a biometric factor, satisfying the requirement for factors from different categories. Combining a password with a security question answer uses two knowledge factors, which constitutes single-factor authentication regardless of how many questions are asked. A single complex password, no matter how strong, remains one factor. Combining a password with a PIN also uses two knowledge factors rather than two different factor categories, so it does not qualify as MFA.
4. A security analyst at Fabrikam Technology is using the Open FAIR methodology to quantify cyber risk for a web application. Threat intelligence indicates that a particular threat agent attempts to exploit the application approximately 50 times per year. Historical analysis shows that the threat agent's actions result in a successful loss event 20% of the time. The analyst needs to calculate the Loss Event Frequency for this risk scenario. What is the correct Loss Event Frequency according to Open FAIR terminology? (Select one!)
Explanation
In Open FAIR, Loss Event Frequency (LEF) is calculated by multiplying Threat Event Frequency (TEF) by Vulnerability. Vulnerability is defined as the probability (expressed as a percentage or decimal) that a threat event will result in a successful loss event. In this scenario, LEF = TEF x Vulnerability = 50 x 0.20 = 10 loss events per year. The Threat Event Frequency of 50 represents how often the threat agent acts, not how often losses occur. Multiplying TEF by Vulnerability directly yields LEF as a frequency measure of actual loss occurrences. Loss Magnitude is a separate Open FAIR component representing financial impact, and is not involved in this calculation.
5. During an enterprise architecture governance review at Contoso Manufacturing, a senior business architect argues that implementing strong security controls will inevitably restrict the organization's ability to share information across departmental and partner boundaries, conflicting with the enterprise's digital collaboration strategy. A security architect responds by explaining the G152 position on Boundaryless Information Flow™. Which statement best represents the G152 perspective on the relationship between security and information flow? (Select one!)
Explanation
G152 explicitly supports The Open Group's vision of Boundaryless Information Flow™ — the ability to share information seamlessly and securely across organizational, technical, and geographic boundaries. The G152 position is that well-designed security should act as an enabler of information sharing rather than an obstacle to it. Security controls should be proportionate to actual risk, aligned with genuine business requirements, implemented consistently across trust boundaries, and transparent in their operation so stakeholders understand what is protected and why. G152 does not concede that security must restrict information flow; it argues that security architecture designed from the outset alongside the enterprise architecture will support rather than impede collaboration objectives. Creating a separate security domain gatekeeper contradicts the cross-cutting integration philosophy that G152 and the TOGAF ADM promote. Unconditionally prioritizing security over all business objectives contradicts the risk-proportionate, business-aligned approach that G152 advocates throughout.
TOGAF® Enterprise Architecture Leader
TOGAF EA Leader · 598 questions
TOGAF® Enterprise Architecture Part 2 Exam (OGEA-102)
OGEA-102 · 600 questions
TOGAF® Framework Digital Specialist
OG0-DS1 · 598 questions
The Open Group Certified: TOGAF® Framework Agile Specialist
TOGAF-Agile-Specialist · 589 questions
TOGAF® Business Architecture Foundation (OGBA-101)
OGBA-101 · 600 questions
TOGAF® Enterprise Architecture Foundation (OGEA-101)
OGEA-101 · 600 questions
$17.99
One-time access to this exam