IASA Certified IT Architect – Associate (CITA-A) Information Technology Architecture — Questions and Answers
Question 1: A new IT project is in its initiation phase. The project sponsor has a high level of authority but limited availability and technical knowledge. According to stakeholder management best practices, what is the BEST engagement strategy for this sponsor?
- Provide periodic, concise summaries focused on business outcomes, risks, and key decision points. (Correct answer)
- Involve them in every technical design decision to ensure their approval.
- Minimize contact to avoid taking up their valuable time.
- Send them daily, detailed technical progress reports to keep them fully informed.
Correct answer: Provide periodic, concise summaries focused on business outcomes, risks, and key decision points.
This stakeholder fits into the "High Power, Low Interest" (or low engagement) quadrant of a Power/Interest grid, where the recommended strategy is to "Keep Satisfied". This involves providing high-level summaries that respect their time while keeping them informed of progress against business goals and highlighting any critical issues that require their authority. Overloading them with technical detail (A, C) or ignoring them (D) are both ineffective and risky strategies.
Question 2: In a scenario where a company is undergoing a digital transformation to improve customer experience, a business architect needs to model the end-to-end sequence of activities that deliver a specific product or service to the customer. Which modeling technique should be prioritized?
- Information Mapping
- Capability Mapping
- Organizational Mapping
- Value Stream Mapping (Correct answer)
Correct answer: Value Stream Mapping
Value Stream Mapping is specifically designed to illustrate the sequence of activities required to deliver value to a customer or stakeholder. It helps identify waste, streamline processes, and improve the overall customer journey, making it essential for a customer experience-focused transformation.
Question 3: An e-commerce platform for a major sporting event is preparing for a ticket sale that is expected to cause a massive, short-term surge in user traffic for a few hours. Which quality attribute BEST describes the system's ability to automatically provision resources to handle this peak load and then de-provision them afterwards to minimize costs?
- Scalability
- Availability
- Elasticity (Correct answer)
- Fault Tolerance
Correct answer: Elasticity
Elasticity is the specific quality attribute that refers to a system's ability to dynamically and automatically add or remove resources to match fluctuating workload demands in real-time. While related to scalability, elasticity is distinct in its automated, on-demand nature, which is crucial for handling sudden traffic spikes and optimizing costs. [2, 5, 9]
Question 4: An architect specifies that a new application's service account, which is used to process automated reports, must only have read-only access to a specific database table and no other permissions within the system. Which fundamental security design principle does this specification enforce?
- Open Design
- Defense-in-Depth
- Principle of Least Privilege (Correct answer)
- Separation of Duties
Correct answer: Principle of Least Privilege
The Principle of Least Privilege (PoLP) dictates that a user, program, or process should have only the minimum necessary access rights (or permissions) to perform its specific function. By restricting the service account to only read-only access for a single table, the architect is strictly applying this principle.
Question 5: During an architecture design workshop, a junior business analyst continually challenges the architect's recommendations without providing data-backed alternatives. This is disrupting the meeting and slowing progress. Which of the following is the MOST appropriate conflict resolution technique for the architect to use in the moment?
- Ignore the analyst's comments and continue with the presentation as planned.
- Acknowledge the analyst's concern, ask for specific data or examples to be provided offline, and park the issue to be addressed separately. (Correct answer)
- Publicly reprimand the analyst for being disruptive to assert authority.
- End the meeting immediately and reschedule it without inviting the junior analyst.
Correct answer: Acknowledge the analyst's concern, ask for specific data or examples to be provided offline, and park the issue to be addressed separately.
This approach is professional and effective for conflict resolution. It validates the individual's right to have a concern, holds them accountable for substantiating it, and maintains the meeting's momentum by parking the issue. Publicly reprimanding is unprofessional, ignoring the issue can let it fester, and ending the meeting is an overreaction that punishes all attendees.
Question 6: Which framework is often used to support business & IT alignment?
- HTML5
- Agile UX
- TOGAF (Correct answer)
- CSS
Correct answer: TOGAF
TOGAF (The Open Group Architecture Framework) is a widely recognized enterprise architecture framework that provides a comprehensive approach for designing, planning, implementing, and governing an enterprise information technology architecture. It helps organizations align their IT strategy with their business strategy by providing a structured methodology for developing and managing enterprise architecture.
Question 7: Which protocol assigns IP addresses dynamically?
- DHCP (Correct answer)
- HTTP
- FTP
- SMTP
Correct answer: DHCP
DHCP (Dynamic Host Configuration Protocol) is a network management protocol used on Internet Protocol (IP) networks for dynamically assigning IP addresses and other communication parameters to devices connected to the network. This automation simplifies network administration by eliminating the need for manual IP configuration for each device, ensuring efficient network setup and management.
Question 8: Which method helps ensure consistent data across systems?
- Data synchronization (Correct answer)
- Data filtering
- Data replication only
- Data scrambling
Correct answer: Data synchronization
Data synchronization is a process that ensures consistency of data across multiple systems or locations. It involves automatically updating data in one system when changes occur in another, maintaining a unified and accurate view of information. This method is crucial for preventing discrepancies and ensuring that all integrated applications operate with the most current and reliable data.
Question 9: What is an ETL process?
- Edit Table Layout
- Evaluate Temporary Logs
- Export Text Lines
- Extract, Transform, Load (Correct answer)
Correct answer: Extract, Transform, Load
ETL stands for Extract, Transform, Load, which is a three-phase process used to integrate data from various sources into a data warehouse or another target system. In the 'Extract' phase, data is retrieved from source systems. The 'Transform' phase cleanses, standardizes, and converts the data into a suitable format. Finally, the 'Load' phase delivers the transformed data into the destination system.
Question 10: A 'Transition Architecture' in TOGAF represents:
- The governance framework for managing architecture change
- A simplified version of the target architecture for executive communication
- An interim architecture state that bridges baseline and target architectures (Correct answer)
- The current baseline state of the enterprise architecture
Correct answer: An interim architecture state that bridges baseline and target architectures
A Transition Architecture in TOGAF represents a series of intermediate architectures that provide stepping stones between the baseline and target architectures during implementation.
Question 11: Why is redundancy important in network infrastructure?
- Prevents unauthorized access
- Slows the network
- Maintains service during failures (Correct answer)
- Reduces costs
Correct answer: Maintains service during failures
Redundancy in network infrastructure involves duplicating critical components or paths to ensure that if one component fails, another can take over seamlessly. This design principle is crucial for maintaining high availability and preventing service disruptions. It minimizes downtime and ensures continuous operation, which is vital for business continuity and reliable service delivery.
Question 12: Which topology uses a central hub to connect all nodes?
- Star (Correct answer)
- Ring
- Mesh
- Bus
Correct answer: Star
In a star topology, all network devices (nodes) are individually connected to a central hub, switch, or server. This central device acts as a conduit for all data traffic between the nodes. If one node fails, it does not affect the rest of the network, but if the central device fails, the entire network goes down.
Question 13: An IT architect is selecting an enterprise architecture framework for a large financial institution. Which factor should be given highest priority when making this selection?
- The number of certified practitioners available in the market
- The framework's age and historical track record
- Alignment with the organization's industry, scale, and governance needs (Correct answer)
- The cost of licensing and tooling associated with the framework
Correct answer: Alignment with the organization's industry, scale, and governance needs
Framework selection should primarily be driven by how well it aligns with the organization's specific industry context, scale of operations, and existing governance structures to ensure practical applicability.
Question 14: In TOGAF, what is the primary output of Phase E (Opportunities and Solutions)?
- An initial complete version of the Architecture Roadmap (Correct answer)
- The Stakeholder Map and engagement plan
- The Architecture Definition Document
- The Target Architecture document
Correct answer: An initial complete version of the Architecture Roadmap
Phase E (Opportunities and Solutions) produces the initial complete version of the Architecture Roadmap, which identifies work packages, transition architectures, and an implementation and migration plan.
Question 15: During the design of a complex system, the lead architect insists that every major component must be designed in a way that allows it to be verified independently through automated scripts and that it exposes diagnostic endpoints. This practice directly enhances which quality attribute?
- Security
- Scalability
- Usability
- Testability (Correct answer)
Correct answer: Testability
Testability refers to the degree to which a system or component facilitates the creation and execution of tests to determine if it meets its specified requirements. [7, 11] Designing for independent verification and including diagnostic endpoints are key architectural tactics to improve a system's overall testability.
Question 16: An IT architect is designing a new data architecture for a financial services company. A key requirement is to ensure that data is accurate, consistent, and reliable to support regulatory reporting and business analytics. Which of the following disciplines is most critical for achieving this requirement?
- Data Governance (Correct answer)
- Database Administration
- Data Warehousing
- Data Migration
Correct answer: Data Governance
Data governance is the formal framework of policies, processes, and controls that ensure an organization's data assets are managed effectively. [11] It is essential for maintaining data quality, security, and compliance, which are crucial for reliable reporting and analytics in a regulated industry. [10, 15] While other disciplines are important, data governance provides the overarching structure for data integrity.
Question 17: Which role typically leads efforts to align IT with business strategy?
- Database administrator
- Software engineer
- Technical writer
- Chief Information Officer (CIO) (Correct answer)
Correct answer: Chief Information Officer (CIO)
The Chief Information Officer (CIO) is a senior executive responsible for overseeing an organization's information technology strategy and implementation. A key part of their role is bridging the gap between IT capabilities and business needs, ensuring that technology initiatives are aligned with and contribute to the company's strategic objectives. They act as a liaison between technical teams and business leadership.
Question 18: An organization has adopted a "Cloud First" strategy as a key architectural principle. What is the primary implication of this principle for new technology and infrastructure decisions?
- On-premises solutions are to be considered only after cloud-based options are evaluated and found unsuitable. (Correct answer)
- All new applications must be built using microservices.
- Data analytics and reporting must be physically separated from operational databases.
- The organization must exclusively use a single public cloud provider to ensure standardization.
Correct answer: On-premises solutions are to be considered only after cloud-based options are evaluated and found unsuitable.
A "Cloud First" principle means that for any new solution or service, cloud-based options (SaaS, PaaS, IaaS) should be the default consideration. On-premises deployments are only chosen if there's a compelling technical, security, or regulatory reason why a cloud solution is not feasible.
Question 19: A company's new business strategy calls for rapid innovation and experimentation with new digital products. The existing IT infrastructure is rigid and slow to change. This situation represents a misalignment between business strategy and which key component of technology strategy?
- Vendor management.
- IT asset inventory.
- Required business capabilities. (Correct answer)
- IT budget and cost allocation.
Correct answer: Required business capabilities.
Business capability mapping is the process of identifying what a business must be able to do to execute its strategy. In this scenario, the business strategy requires the 'capability' of rapid innovation and experimentation. The rigid IT infrastructure shows a gap between the required business capabilities and the current IT capabilities, which the business technology strategy must address.
Question 20: Which architecture framework is known for its matrix-based structure, organized around stakeholder perspectives (e.g., Planner, Owner, Designer) and interrogatives (What, How, Where, Who, When, Why)?
- ArchiMate
- DoDAF (Department of Defense Architecture Framework)
- Zachman Framework (Correct answer)
- TOGAF (The Open Group Architecture Framework)
Correct answer: Zachman Framework
The Zachman Framework is fundamentally a taxonomy or ontology for organizing architectural artifacts. It is well-known for its two-dimensional matrix structure that uses interrogatives (What, How, Where, etc.) for columns and stakeholder perspectives (Planner, Owner, etc.) for rows.
Question 21: Why is middleware important in integration?
- Hosts websites
- Deletes old logs
- Increases storage capacity
- Acts as a bridge between systems (Correct answer)
Correct answer: Acts as a bridge between systems
Middleware is software that acts as an intermediary layer between different applications, systems, or components. Its importance in integration lies in its ability to facilitate communication, data exchange, and process coordination between disparate systems that might otherwise be incompatible. Middleware handles tasks like data translation, message queuing, and transaction management, effectively bridging the gap between various technologies.
Question 22: Which framework provides guidelines for managing information security?
- CMMI
- Agile
- NIST (Correct answer)
- Waterfall
Correct answer: NIST
NIST, the National Institute of Standards and Technology, provides widely recognized and respected frameworks and guidelines for managing information security. The NIST Cybersecurity Framework, for example, offers a flexible and comprehensive approach for organizations to assess and improve their ability to prevent, detect, and respond to cyberattacks. These guidelines are adopted globally to enhance security practices.
Question 23: An enterprise is transitioning its monolithic e-commerce platform to a microservices architecture. Which of the following is the primary advantage the enterprise can expect from this transition in terms of application architecture?
- A unified codebase for easier development and deployment.
- Increased agility and the ability to scale services independently. (Correct answer)
- Reduced operational complexity and infrastructure costs.
- Simplified debugging and end-to-end testing processes.
Correct answer: Increased agility and the ability to scale services independently.
Microservices architecture structures an application as a collection of loosely coupled services. This allows for individual services to be developed, deployed, and scaled independently, which significantly increases business agility and improves the application's scalability and resilience. [9, 13] While monolithic applications can be simpler to deploy initially, they become difficult to scale and maintain as they grow. [9, 14]
Question 24: When using the Zachman Framework, at which row (perspective) would a database administrator primarily work?
- Row 3: System Model (Designer perspective)
- Row 4: Technology Model (Builder perspective)
- Row 2: Business Model (Owner perspective)
- Row 5: Detailed Representations (Implementer perspective) (Correct answer)
Correct answer: Row 5: Detailed Representations (Implementer perspective)
Database administrators work at Row 4 (Technology Model / Builder perspective), where physical database schemas, stored procedures, and actual data storage technologies are defined.
Question 25: A retail company is building a cloud-native application. The architects have decided to prioritize stateless processing for most of the application's components. What is the main benefit of this architectural choice in a cloud environment?
- It simplifies data consistency and transactional integrity.
- It reduces the need for a robust data access layer.
- It minimizes network latency between application components.
- It enhances scalability and fault tolerance by not storing session data on the instance. (Correct answer)
Correct answer: It enhances scalability and fault tolerance by not storing session data on the instance.
Stateless processing is a core principle of cloud-native applications. By not storing client session data on the server, any instance can handle any request. This makes it much easier to scale the application horizontally by adding or removing instances and improves resilience, as the failure of one instance does not result in data loss. [3]
Question 26: Which metric best evaluates IT-business alignment?
- Return on Investment (ROI) (Correct answer)
- Amount of code written.
- Server uptime in hours.
- IT team size.
Correct answer: Return on Investment (ROI)
Return on Investment (ROI) is a crucial metric for evaluating IT-business alignment because it quantifies the financial benefits derived from IT investments relative to their costs. A positive ROI indicates that IT initiatives are generating tangible value and contributing to the organization's financial success, directly demonstrating their alignment with business objectives. It measures the effectiveness of IT in achieving business outcomes.
Question 27: A business architect is tasked with creating a model that defines what an organization does to achieve its strategic objectives, independent of how it does it. Which of the following business architecture models would be most appropriate for this purpose?
- A business capability map (Correct answer)
- An organizational chart
- A value stream map
- A process model
Correct answer: A business capability map
A business capability map focuses on the fundamental abilities or functions of a business (the 'what'), abstracting away from specific processes, organizational structures, or technologies (the 'how'). This makes it the ideal model for representing the stable, core functions needed to execute business strategy.
Question 28: Why is employee training essential for security?
- Changes job roles
- Prevents system updates
- Reduces vacation time
- Improves awareness and threat response (Correct answer)
Correct answer: Improves awareness and threat response
Employee training is crucial for security because human error is a leading cause of security breaches. Well-trained employees are more aware of common threats like phishing, social engineering, and malware, and understand their role in protecting sensitive information. This improved awareness enables them to identify and respond appropriately to potential security incidents, significantly strengthening an organization's overall security posture.
Question 29: What is the primary goal of risk management in IT?
- Reduce hardware size
- Minimize the impact of security threats (Correct answer)
- Increase coding speed
- Automate backups
Correct answer: Minimize the impact of security threats
Risk management in IT is a systematic process of identifying, assessing, and controlling threats to an organization's information assets. Its primary goal is not to eliminate all risks, which is often impossible, but rather to minimize the potential negative impact of security threats and vulnerabilities on business operations and data. This ensures business continuity and protects valuable information.
Question 30: In the Zachman Framework, what does the column representing 'When' address?
- Functional processes
- Network locations and nodes
- Timing and scheduling (events and cycles) (Correct answer)
- Data and information assets
Correct answer: Timing and scheduling (events and cycles)
The 'When' column in the Zachman Framework addresses timing, scheduling, events, and cycles within an enterprise architecture.
Question 31: An organization's enterprise architect is evaluating two application architecture patterns: Monolithic and Microservices. The project is a small, internal application with a limited budget, a small development team, and a need for rapid initial deployment. Which pattern is likely the most suitable choice and why?
- Microservices, because it allows for greater technological diversity and scalability from the start.
- Monolithic, because it offers lower initial complexity, simplified deployment, and is easier for a small team to manage. [13, 14] (Correct answer)
- Microservices, because it enforces a loosely coupled architecture, which is always superior.
- Monolithic, because it is inherently more secure due to having a single attack surface.
Correct answer: Monolithic, because it offers lower initial complexity, simplified deployment, and is easier for a small team to manage. [13, 14]
For smaller projects with limited resources and a need for quick deployment, a monolithic architecture is often the better choice. [9, 13] It avoids the significant operational overhead and complexity associated with managing a distributed microservices system, such as service discovery, inter-service communication, and distributed data management. [16] The simplicity of a single codebase and deployment unit is advantageous in this scenario. [14]
Question 32: Which technique within enterprise architecture practice involves creating a simplified representation of the enterprise to understand and communicate complex relationships between business and IT?
- Value Chain Analysis
- Gap Analysis
- Architecture Patterns
- Architecture Modeling (Correct answer)
Correct answer: Architecture Modeling
Architecture Modeling involves creating simplified, purposeful representations of enterprise components and their relationships to facilitate understanding, communication, and decision-making among stakeholders.
Question 33: An IT architect is designing a new enterprise-wide data analytics platform. The business intelligence team is a key stakeholder and has expressed strong opinions about specific tools they want to use, which conflict with the established enterprise technology standards. What is the MOST effective initial approach for the architect?
- Acknowledge their input and facilitate a trade-off analysis to evaluate their preferred tools against the enterprise standards and project requirements. (Correct answer)
- Exclude the business intelligence team from further design discussions to avoid delays.
- Immediately approve their preferred tools to ensure their buy-in for the project.
- Escalate the conflict to the Architecture Review Board to enforce the standard.
Correct answer: Acknowledge their input and facilitate a trade-off analysis to evaluate their preferred tools against the enterprise standards and project requirements.
The best approach is collaborative. Acknowledging stakeholder input and conducting a formal trade-off analysis respects their expertise while maintaining architectural discipline. It allows for a decision based on facts (requirements, costs, risks) rather than just preference or policy. Escalating immediately is adversarial, approving without analysis is irresponsible, and excluding them guarantees project failure.
Question 34: Which of the following BEST describes the primary purpose of an organization map within the context of business architecture?
- To detail the hierarchical reporting structure and individual employee titles.
- To link business units to the capabilities they possess and the value streams they participate in. (Correct answer)
- To provide a real-time visualization of inter-departmental communication flows.
- To document all business processes executed by each department.
Correct answer: To link business units to the capabilities they possess and the value streams they participate in.
Unlike a traditional org chart, an organization map in business architecture is used to show how various business units relate to other architectural elements, such as capabilities and value streams. Its purpose is to provide structural context for how the business operates, not to detail HR-specific reporting lines.
Question 35: The Federal Enterprise Architecture Framework (FEAF) organizes architecture into reference models. Which reference model focuses on the performance outcomes and indicators for government services?
- Data Reference Model (DRM)
- Business Reference Model (BRM)
- Performance Reference Model (PRM) (Correct answer)
- Service Component Reference Model (SRM)
Correct answer: Performance Reference Model (PRM)
The Performance Reference Model (PRM) in FEAF provides a framework for measuring the performance of IT investments and their contribution to program and agency outcomes.
Question 36: What is the purpose of application integration?
- Deletes duplicate apps
- Reduces software lifespan
- Allows systems to communicate and collaborate (Correct answer)
- Restricts data flow
Correct answer: Allows systems to communicate and collaborate
Application integration is the process of enabling different software applications to work together seamlessly, sharing data and functionality. Its primary purpose is to break down data silos and allow disparate systems to communicate, exchange information, and collaborate efficiently. This improves business processes, reduces manual effort, and provides a unified view of data across the organization.
Question 37: An organization is establishing its architecture governance framework. Which of the following is a primary responsibility of an Architecture Review Board (ARB)?
- Ensuring that technology projects and initiatives align with the organization's architectural framework and strategic goals. (Correct answer)
- Procuring hardware and software licenses for approved projects.
- Developing and deploying software applications based on architectural designs.
- Providing day-to-day project management for technology initiatives.
Correct answer: Ensuring that technology projects and initiatives align with the organization's architectural framework and strategic goals.
The core function of an Architecture Review Board (ARB) is to provide oversight and ensure that all technology initiatives are in alignment with the established enterprise architecture, standards, and business strategies. This governance role helps maintain consistency, manage risk, and ensure that technology investments support long-term objectives.
Question 38: In stakeholder management, what is the primary purpose of using a Power/Interest grid?
- To define the specific tasks and work assignments for project team members.
- To document detailed minutes from every stakeholder meeting.
- To classify stakeholders to determine the appropriate level and frequency of engagement. (Correct answer)
- To calculate the financial impact of each stakeholder's requirements.
Correct answer: To classify stakeholders to determine the appropriate level and frequency of engagement.
A Power/Interest grid is a stakeholder analysis tool used to group stakeholders based on their level of authority (power) and their level of concern (interest) in the project. This classification helps architects tailor communication and engagement strategies, ensuring key stakeholders are managed closely while others are kept informed appropriately.
Question 39: A healthcare organization is defining its Business Technology Strategy with a strong focus on data security and regulatory compliance. Which component of the strategy should be given the highest priority?
- Business capability mapping.
- Technology modernization roadmap.
- Security, governance, and risk management framework. (Correct answer)
- IT personnel and management structure.
Correct answer: Security, governance, and risk management framework.
For an industry like healthcare with stringent data security and compliance requirements (e.g., HIPAA), the governance, security, and risk management framework is paramount. This component defines the policies, standards, and controls necessary to protect sensitive information and ensure adherence to legal mandates, forming a foundation of trust upon which all other technology initiatives are built.
Question 40: What is the primary objective of an Architecture Communications Plan?
- To track the budget and spending for all IT architecture-related activities.
- To create a central repository for all final architecture design documents.
- To define the target audiences, key messages, communication channels, and frequency for sharing information about the architecture. (Correct answer)
- To serve as a formal contract between the architecture team and the project management office.
Correct answer: To define the target audiences, key messages, communication channels, and frequency for sharing information about the architecture.
An Architecture Communications Plan is a strategic document that outlines the proactive approach to stakeholder communication. Its purpose is to ensure that the right information reaches the right people at the right time through the most effective channel. This helps to manage expectations, secure buy-in, and facilitate governance.
Question 41: Which tool monitors data flow between systems?
- Calendar app
- Firewall
- Integration dashboard (Correct answer)
- Email server
Correct answer: Integration dashboard
An integration dashboard is a centralized tool or interface designed to provide real-time visibility and monitoring of data flow and processes between integrated systems. It allows administrators to track the status of integrations, identify errors, monitor performance, and gain insights into the overall health of the integrated environment. This helps in proactive management and troubleshooting of integration issues.
Question 42: The Open Group Architecture Framework (TOGAF) categorizes architectures into four domains. Which domain specifically addresses the software applications, their interactions, and relationships to business processes?
- Data Architecture
- Technology Architecture
- Application Architecture (Correct answer)
- Business Architecture
Correct answer: Application Architecture
Application Architecture in TOGAF defines the individual application systems deployed, their interactions, and their relationships to core business processes of the organization.
Question 43: What is the main goal of aligning IT strategy with business objectives?
- To achieve business goals through IT enablement. (Correct answer)
- To reduce hardware costs.
- To upgrade systems annually.
- To increase software licenses.
Correct answer: To achieve business goals through IT enablement.
The primary purpose of aligning IT strategy with business objectives is to ensure that technology investments and initiatives directly support and drive the organization's overarching goals. IT is not merely a support function but a strategic enabler that can create competitive advantages, improve efficiency, and facilitate innovation. This alignment ensures IT resources are utilized to maximize business value.
Question 44: In the context of architecture governance, which of the following is NOT considered a core component of a governance framework?
- Clearly defined roles and responsibilities.
- A set of defined processes for review and compliance.
- Specific software vendor selection and contract negotiation. (Correct answer)
- Published standards and guidelines.
Correct answer: Specific software vendor selection and contract negotiation.
An architecture governance framework defines the structure, processes, and standards for making architectural decisions. Its core components include defining roles, responsibilities, processes, and standards. While the outputs of the governance process will influence vendor selection, the act of selecting specific vendors and negotiating contracts is typically a procurement or project management function, not a core component of the governance framework itself.
Question 45: What type of cable is commonly used in Ethernet networks?
- Fiber
- Coaxial
- Twisted pair (Correct answer)
- HDMI
Correct answer: Twisted pair
Twisted pair cable, particularly unshielded twisted pair (UTP), is the most common type of cabling used for wired Ethernet networks. It consists of pairs of insulated wires twisted together to reduce electromagnetic interference and crosstalk. This type of cable is cost-effective and supports various Ethernet standards, making it ideal for connecting devices in local area networks.
Question 46: Why is data mapping important?
- Deletes unused fields
- Hides metadata
- Aligns data formats for accurate transfer (Correct answer)
- Encrypts all fields
Correct answer: Aligns data formats for accurate transfer
Data mapping is the process of creating a link between two distinct data models, defining how data elements from one source correspond to data elements in a target system. It is crucial for integration because it ensures that data is accurately and consistently transferred between applications, despite differences in their underlying structures or formats. Proper data mapping prevents data loss, corruption, or misinterpretation during integration.
Question 47: Which enterprise architecture principle states that technology decisions should be made to minimize the diversity of technology components across the enterprise?
- Interoperability
- Vendor Independence
- Technology Standardization (Correct answer)
- Scalability
Correct answer: Technology Standardization
Technology Standardization as an EA principle advocates for reducing the variety of technology components to lower maintenance costs, simplify support, and improve integration across the enterprise.
Question 48: An architect is evaluating different virtualization techniques for a data center refresh. They decide to partition a single physical server into multiple isolated virtual servers, each with its own operating system. What is this technique called?
- Server Virtualization (Correct answer)
- Application Virtualization
- Network Virtualization
- Storage Virtualization
Correct answer: Server Virtualization
Server virtualization is the process of partitioning a physical server into multiple, isolated virtual servers. Each virtual server can run its own operating system and applications independently, leading to more efficient resource utilization.
Question 49: When developing a business technology strategy, an architect uses the TOGAF framework. What is the primary benefit of using a well-established framework like TOGAF?
- It provides a specific, pre-built architecture that can be implemented immediately.
- It guarantees the selection of the lowest-cost technology vendors.
- It provides a structured, repeatable methodology for aligning technology with business goals. (Correct answer)
- It eliminates the need for stakeholder communication and management.
Correct answer: It provides a structured, repeatable methodology for aligning technology with business goals.
Frameworks like TOGAF (The Open Group Architecture Framework) provide a proven, structured method for developing an IT architecture that meets business needs. Its key benefit is offering a reliable process (the Architecture Development Method - ADM) to ensure that the architecture is well-planned, aligned with business objectives, and implemented effectively, rather than providing a one-size-fits-all solution.
Question 50: A project team is focused on improving the efficiency of a specific workflow for processing insurance claims. They are detailing every step, decision point, and system interaction. This activity is an example of:
- Strategic Planning
- Organizational Mapping
- Business Capability Modeling
- Business Process Modeling (Correct answer)
Correct answer: Business Process Modeling
Business Process Modeling involves defining the specific sequence of activities, tasks, and rules to accomplish a particular business outcome. This is distinct from Business Capability Modeling, which defines *what* the business can do (e.g., 'Claims Adjudication'), not *how* it does it.
Question 51: What challenge can arise in application integration?
- Increased battery usage
- More hardware required
- Too much compatibility
- Data format inconsistency (Correct answer)
Correct answer: Data format inconsistency
A significant challenge in application integration is dealing with data format inconsistency across different systems. Applications often store and represent data in varying structures, types, and conventions, which can hinder seamless communication. Overcoming this requires extensive data mapping and transformation efforts to ensure that data exchanged between systems is correctly interpreted and processed.
Question 52: When developing a business capability model, a common best practice is to ensure the capabilities are MECE. What does this acronym stand for?
- Mainly Exclusive, Commonly Exhaustive
- Model Everything, Chart Everything
- Mission Essential, Critically Executable
- Mutually Exclusive, Collectively Exhaustive (Correct answer)
Correct answer: Mutually Exclusive, Collectively Exhaustive
MECE, or Mutually Exclusive, Collectively Exhaustive, is a principle used to ensure that capabilities are distinct and non-overlapping (mutually exclusive) while covering the entire scope of the business without gaps (collectively exhaustive). This ensures a clear, logical, and complete capability map.
Question 53: During the security architecture design phase for a new cloud-native application, an architect leads a structured exercise to identify and evaluate potential security flaws from an attacker's perspective. What is this proactive process called?
- Vulnerability Scanning
- Penetration Testing
- Security Audit
- Threat Modeling (Correct answer)
Correct answer: Threat Modeling
Threat modeling is a structured, proactive process used early in the development lifecycle to identify, analyze, and mitigate potential security threats and architectural weaknesses before the system is built. Penetration testing and vulnerability scanning are typically performed on a system that has already been built.
Question 54: What is a zero-day vulnerability?
- A known malware
- A printer error
- A security flaw with no known patch (Correct answer)
- A password change policy
Correct answer: A security flaw with no known patch
A zero-day vulnerability refers to a software flaw that is unknown to the vendor or for which no official patch or fix has been released yet. Attackers can exploit these vulnerabilities before developers have a chance to address them, making them particularly dangerous. The term 'zero-day' signifies that developers have had zero days to fix the issue since it became known to attackers.
Question 55: A financial services firm is undergoing a digital transformation. The enterprise architect has been tasked with creating a technology strategy that fosters agility and adaptability to respond to market changes. Which of the following approaches would BEST support this objective?
- Standardizing on a single, comprehensive technology stack to reduce complexity.
- Implementing a flexible and scalable IT architecture, such as one based on microservices and cloud-native principles. (Correct answer)
- Creating a highly detailed, five-year technology roadmap with fixed project timelines and budgets.
- Prioritizing short-term cost reduction by extending the life of legacy systems.
Correct answer: Implementing a flexible and scalable IT architecture, such as one based on microservices and cloud-native principles.
To achieve agility and adaptivity, the technology strategy must support rapid change. A flexible and scalable architecture, like one using microservices and cloud computing, allows the organization to handle increased demands and adapt to market shifts efficiently without sacrificing performance. This approach enables faster development cycles and easier modification of individual services, directly contributing to business agility.
Question 56: Which TOGAF ADM phase is responsible for confirming that the architecture sponsor and key stakeholders are committed to proceeding, and that there is a clear statement of the enterprise's aspirations for change?
- Phase B: Business Architecture
- Phase A: Architecture Vision (Correct answer)
- Preliminary Phase
- Phase H: Architecture Change Management
Correct answer: Phase A: Architecture Vision
Phase A (Architecture Vision) is where the scope, constraints, and expectations for the architecture engagement are defined, and stakeholder commitment is secured before proceeding with detailed architecture work.
Question 57: To meet stringent data protection regulations, an architect designs a system to perform multiple layers of data encryption and cryptographic signing for every transaction. This design choice is most likely to create a negative trade-off with which other critical quality attribute?
- Modularity
- Performance (Correct answer)
- Availability
- Reliability
Correct answer: Performance
Security measures, particularly computationally intensive ones like multi-layer encryption and digital signatures, add processing overhead. For each transaction, the system must perform extra work, which increases latency and reduces overall throughput. This creates a common trade-off where enhancing security can negatively impact performance. [1]
Question 58: When defining the Technology Architecture domain within an overall Enterprise Architecture, which of the following is the primary focus?
- Detailing the hardware, software infrastructure, and network components. (Correct answer)
- Specifying the logical software and application components.
- Describing how data is stored, managed, and governed.
- Defining the business strategy and organizational structure.
Correct answer: Detailing the hardware, software infrastructure, and network components.
The Technology Architecture domain focuses on the foundational technology infrastructure that supports the entire enterprise. This includes the physical and virtual hardware, operating systems, networking equipment, and other core technology services that applications and data rely on.
Question 59: Which TOGAF concept refers to reusable, packaged solutions that provide specific business functions and can be assembled to build complete enterprise architectures?
- Architecture Building Blocks (ABBs)
- Reference Models
- Solution Building Blocks (SBBs) (Correct answer)
- Architecture Patterns
Correct answer: Solution Building Blocks (SBBs)
Solution Building Blocks (SBBs) in TOGAF represent specific products or components that fulfill Architecture Building Blocks (ABBs) and can be directly implemented in the enterprise.
Question 60: An IT architect is explaining system quality attributes to a project stakeholder. Which statement best distinguishes 'Availability' from 'Reliability'?
- Availability is a measure of system uptime, while Reliability is a measure of how quickly the system can be repaired.
- Reliability is measured in 'nines' (e.g., 99.99%), while Availability is measured by Mean Time Between Failures (MTBF).
- Availability is the probability that a system is operational at any given moment, while Reliability is the probability it will operate correctly without failure over a specified duration. [15, 17] (Correct answer)
- Reliability focuses on preventing all failures, whereas Availability is only concerned with network accessibility.
Correct answer: Availability is the probability that a system is operational at any given moment, while Reliability is the probability it will operate correctly without failure over a specified duration. [15, 17]
Availability refers to a system's readiness to perform its function at a specific point in time, often expressed as a percentage of uptime. Reliability, on the other hand, measures the likelihood of a system performing its function without failure for a continuous period under stated conditions. A system can be highly available but not very reliable if it fails frequently but recovers instantly. [15, 17]
Question 61: Which framework was specifically developed by the US Government to provide a common approach to federal IT planning and investment, incorporating five reference models aligned to government services?
- TOGAF (The Open Group Architecture Framework)
- FEAF (Federal Enterprise Architecture Framework) (Correct answer)
- MODAF (Ministry of Defence Architecture Framework)
- DoDAF (Department of Defense Architecture Framework)
Correct answer: FEAF (Federal Enterprise Architecture Framework)
FEAF (Federal Enterprise Architecture Framework) was developed specifically for US federal agencies to provide a common taxonomy and ontology for planning and managing IT investments across the government.
Question 62: What is a common tool for aligning IT with strategic goals?
- Login history
- Firewall logs
- Balanced scorecard (Correct answer)
- Source code repository
Correct answer: Balanced scorecard
The Balanced Scorecard is a strategic performance management framework that helps organizations translate their vision and strategy into a comprehensive set of performance measures. It provides a holistic view of organizational performance across financial, customer, internal business process, and learning and growth perspectives. This tool is effective for aligning IT initiatives with strategic goals by linking IT metrics to broader business outcomes.
Question 63: In TOGAF's ADM, the 'Requirements Management' process differs from other phases because it:
- Only operates during the initial phases of the ADM cycle
- Replaces the need for stakeholder analysis in later phases
- Is performed only when architecture requirements change significantly
- Is a continuous process that operates across all ADM phases (Correct answer)
Correct answer: Is a continuous process that operates across all ADM phases
Requirements Management in TOGAF ADM is a continuous process that operates across all phases, ensuring that requirements are identified, stored, and fed into and out of relevant ADM phases.
Question 64: An IT architect is designing a new infrastructure for a financial services company. A key non-functional requirement is to ensure that critical system components have duplicates to prevent a single point of failure and maintain continuous operations. Which architectural principle does this requirement directly address?
- Flexibility
- Redundancy (Correct answer)
- Scalability
- Efficiency
Correct answer: Redundancy
Redundancy is the practice of duplicating critical components or functions of a system to increase reliability. In the event of a failure, the redundant component can take over, ensuring the system remains operational. This is a core principle for achieving high availability.
Question 65: A financial services company is implementing a new architecture governance function. Which of the following metrics would be most effective for measuring the business alignment of their IT architecture?
- The percentage of IT projects that directly support a documented strategic business objective. (Correct answer)
- The average time to approve an architecture design.
- The number of servers decommissioned in the last quarter.
- The number of architecture standards published in the repository.
Correct answer: The percentage of IT projects that directly support a documented strategic business objective.
Business alignment metrics are crucial for demonstrating the value of enterprise architecture. Measuring the percentage of IT projects that are directly linked to strategic business goals provides a clear indicator of how well the IT landscape is supporting the overall mission of the organization. While other metrics are useful for operational efficiency or compliance, this one directly addresses strategic alignment.
Question 66: When applying TOGAF's Architecture Compliance review, what does a 'Consistent' compliance rating indicate?
- The project architecture has not yet been assessed against standards
- The project has met all mandatory architecture requirements
- The project has been modified to address architecture gaps after review
- The project conforms to the spirit of the architecture but may not meet all standards (Correct answer)
Correct answer: The project conforms to the spirit of the architecture but may not meet all standards
A 'Consistent' compliance rating in TOGAF indicates that the project conforms to the general intent of the enterprise architecture but may have gaps in meeting every specific standard or guideline.
Question 67: An organization is shifting its security posture from a traditional perimeter-based model to one that mandates verification for every access request, regardless of whether it originates from inside or outside the corporate network. Which security architecture model BEST represents this modern approach?
- Zero Trust Architecture (Correct answer)
- Castle-and-Moat
- Security Zone Architecture
- Defense-in-Depth
Correct answer: Zero Trust Architecture
Zero Trust Architecture is a security model based on the principle of "never trust, always verify." It requires strict identity verification for every user and device trying to access resources on a private network, eliminating the concept of a trusted internal network.
Question 68: Which TOGAF component provides a structured repository of architecture building blocks, patterns, and reference models?
- Architecture Repository (Correct answer)
- Architecture Development Method (ADM)
- Architecture Capability Framework
- Enterprise Continuum
Correct answer: Architecture Repository
The TOGAF Architecture Repository is a structured repository that holds architectural outputs at different levels of abstraction, including reference models, patterns, and building blocks.
Question 69: A project team proposes a new solution that deviates from the established technology standards. The team argues that the deviation is necessary to meet a critical, time-sensitive business need. Under a mature architecture governance process, what is the formal mechanism for allowing such a temporary deviation?
- A verbal approval from the CIO.
- A project change request.
- An architecture compliance waiver.
- A dispensation. (Correct answer)
Correct answer: A dispensation.
A dispensation is a formal process within architecture governance that grants a project temporary permission to deviate from established standards for a specific period and under defined conditions. This allows for flexibility to meet urgent business needs while ensuring the deviation is tracked, managed, and eventually realigned with the target architecture.
Question 70: What does a firewall do in network design?
- Filters traffic based on security rules (Correct answer)
- Connects switches
- Prints user logs
- Stores backup files
Correct answer: Filters traffic based on security rules
A firewall is a network security system that monitors and controls incoming and outgoing network traffic based on predetermined security rules. Its primary function is to establish a barrier between a trusted internal network and untrusted external networks, like the internet. By filtering traffic, it protects against unauthorized access and malicious activities.
Question 71: In the context of enterprise data architecture, what is the primary role of data modeling?
- To write the ETL (Extract, Transform, Load) scripts for data migration.
- To establish security policies and access controls for the data.
- To define the physical hardware specifications for database servers.
- To create a conceptual blueprint of the data, defining its structure, relationships, and constraints. (Correct answer)
Correct answer: To create a conceptual blueprint of the data, defining its structure, relationships, and constraints.
Data modeling is the process of creating a visual representation or blueprint that defines the data elements and the relationships between them. [12, 17] It is a fundamental part of data architecture that ensures data is organized logically and supports business requirements before any physical database is created. [7]
Question 72: What is the purpose of a security audit?
- Add new users
- Update firewalls
- Delete old logs
- Assess and verify security effectiveness (Correct answer)
Correct answer: Assess and verify security effectiveness
A security audit is a systematic evaluation of an organization's information system security. Its purpose is to assess whether security controls are properly implemented, operating effectively, and compliant with established policies, standards, and regulations. By verifying the effectiveness of security measures, audits help identify weaknesses, ensure adherence to best practices, and provide assurance regarding the protection of information assets.
Question 73: Which of the following BEST describes the primary role of an enterprise architect in the context of Business Technology Strategy?
- To negotiate contracts and manage relationships with all external technology vendors.
- To manage the day-to-day operations of the IT infrastructure and ensure system uptime.
- To bridge the gap between business strategy and technology execution by ensuring alignment. (Correct answer)
- To serve as the lead programmer for the company's most critical software applications.
Correct answer: To bridge the gap between business strategy and technology execution by ensuring alignment.
The core function of an enterprise architect is to ensure that the IT infrastructure and technology solutions are aligned with the organization's business goals. They act as a bridge, translating business strategy into a technology roadmap and governance structure that enables the desired business outcomes.
Question 74: What is a key component of network infrastructure?
- Keyboard
- Printer
- Router (Correct answer)
- Monitor
Correct answer: Router
A router is a fundamental component of network infrastructure that directs data packets between different computer networks. It acts as a traffic controller, determining the best path for information to travel across networks, including the internet. Without routers, devices on separate networks would be unable to communicate with each other.
Question 75: The Department of Defense Architecture Framework (DoDAF) uses 'viewpoints' to organize architectural data. Which DoDAF viewpoint describes operational activities, tasks, and resource flows?
- Operational Viewpoint (OV) (Correct answer)
- Capability Viewpoint (CV)
- Project Viewpoint (PV)
- Systems Viewpoint (SV)
Correct answer: Operational Viewpoint (OV)
The Operational Viewpoint (OV) in DoDAF describes the tasks, activities, operational elements, and resource flows required to conduct operations.
Question 76: What does MFA stand for in security?
- Managed File Access
- Multi-Factor Authentication (Correct answer)
- Main Firewall Agent
- Monitoring for Anomalies
Correct answer: Multi-Factor Authentication
MFA stands for Multi-Factor Authentication, a security enhancement that requires users to provide two or more verification factors to gain access to an account or system. Instead of just a password, it typically combines something you know (password), something you have (phone, token), or something you are (fingerprint, face scan). This layered approach significantly increases security by making it much harder for unauthorized users to access accounts, even if they compromise one factor.
Question 77: Why is stakeholder involvement important in IT strategy?
- It aligns IT with business expectations. (Correct answer)
- It delays planning.
- It adds technical complexity.
- It reduces accountability.
Correct answer: It aligns IT with business expectations.
Involving stakeholders from various business units in IT strategy development ensures that the technology roadmap reflects diverse organizational needs and priorities. This collaborative approach helps to gather critical insights and perspectives, leading to IT solutions that are more relevant and effective. Ultimately, it aligns IT initiatives with the actual expectations and requirements of the business, increasing user adoption and project success.
Question 78: A new project requires the integration of several disparate systems, both internal and external. To ensure that these systems can communicate and exchange data effectively, which architectural principle should be prioritized?
- Interoperability and Standards-Based Integrations (Correct answer)
- Centralization of Core Components
- Complexity Reduction
- Data Redundancy
Correct answer: Interoperability and Standards-Based Integrations
Interoperability is the ability of different systems and organizations to work together (inter-operate). By using standards-based integrations (like REST APIs), an architect ensures that components can be connected and can exchange information in a consistent, predictable manner.
Question 79: An organization is building a new solution that must integrate and exchange data with several existing systems from different vendors, including a cloud-based CRM and an on-premise ERP. The ability of these disparate systems to successfully exchange and make use of information is defined by which quality attribute?
- Reusability
- Portability
- Interoperability (Correct answer)
- Modifiability
Correct answer: Interoperability
Interoperability is the quality attribute that measures the ability of two or more systems or components to exchange information and to use the information that has been exchanged. [6, 14] It is a primary concern when designing solutions that involve integrating multiple, heterogeneous systems.
Question 80: In the context of enterprise architecture maturity models, what does an organization at NASCIO's EA Maturity Level 3 ('Defined') typically demonstrate?
- Quantitative management and measurement of EA processes
- Continuous optimization and improvement of EA practices
- Ad hoc processes with no formal EA documentation
- Documented and standardized EA processes across the organization (Correct answer)
Correct answer: Documented and standardized EA processes across the organization
At NASCIO EA Maturity Level 3 (Defined), organizations have documented, standardized, and communicated EA processes that are consistently applied across the enterprise.
Question 81: A rapidly growing e-commerce company is experiencing performance degradation during peak shopping seasons. The technology architecture must be able to handle significantly increased loads without a major redesign. Which of the following architectural characteristics is most crucial to address this business need?
- Interoperability
- Maintainability
- Security
- Scalability (Correct answer)
Correct answer: Scalability
Scalability refers to the ability of a system to handle a growing amount of work by adding resources. For an e-commerce platform with fluctuating traffic, designing a scalable architecture is essential to maintain performance during high-demand periods.
Question 82: Which type of security focuses on protecting physical devices?
- Physical security (Correct answer)
- Cloud security
- Application security
- Network security
Correct answer: Physical security
Physical security specifically addresses the protection of tangible assets, including hardware, infrastructure, and the physical environment where IT systems reside. This involves measures like access controls (locks, badges), surveillance systems, environmental controls, and fire suppression. Its purpose is to prevent unauthorized physical access, theft, damage, or disruption to IT equipment and facilities.
Question 83: Which of the following scenarios is the BEST example of implementing the 'Defense-in-Depth' principle?
- Using a combination of network firewalls, endpoint anti-malware, data encryption, and multi-factor authentication to protect a critical database. (Correct answer)
- Conducting annual security awareness training for all employees.
- Enforcing a strong password policy for all user accounts.
- Deploying a single, next-generation firewall at the network edge.
Correct answer: Using a combination of network firewalls, endpoint anti-malware, data encryption, and multi-factor authentication to protect a critical database.
Defense-in-Depth is a strategy that employs multiple layers of security controls to protect an asset. The idea is that if one control fails, another is in place to stop an attack. Using firewalls, anti-malware, encryption, and MFA together is a perfect example of this layered approach, whereas the other options represent single security controls.
Question 84: What technology is commonly used for real-time data integration?
- VPN
- API (Correct answer)
- Firewall
- FTP
Correct answer: API
An API (Application Programming Interface) is a set of definitions and protocols that allows different software applications to communicate with each other. APIs are commonly used for real-time data integration because they enable direct, programmatic access to application functionalities and data. This allows systems to request and exchange information instantly, facilitating dynamic and responsive interactions.
Question 85: An architect for a financial institution is designing security controls for a new wealth management platform. To comply with regulations, customer financial data must have stronger encryption and more restrictive access policies than marketing materials. What is the MOST critical prerequisite activity to enable this differentiated approach to security?
- Threat Intelligence Integration
- Data Classification (Correct answer)
- Network Segmentation
- Incident Response Planning
Correct answer: Data Classification
Data classification is the process of categorizing data based on its sensitivity, value, and regulatory requirements. This process is a fundamental prerequisite for applying appropriate security controls, as you cannot protect what you have not identified and valued. Once data is classified, appropriate controls like encryption and access policies can be applied.
Question 86: In the context of enterprise architecture governance, what is the primary role of an Architecture Review Board (ARB)?
- To define and prioritize the organization's business strategy
- To develop and maintain the enterprise architecture artifacts
- To ensure architecture compliance and make decisions on architecture waivers (Correct answer)
- To manage the day-to-day operations of the IT infrastructure
Correct answer: To ensure architecture compliance and make decisions on architecture waivers
An Architecture Review Board (ARB) is responsible for enforcing architecture compliance, reviewing project architectures against enterprise standards, and making decisions on requested deviations or waivers.
Question 87: A business architect is creating an information map. What is the primary focus of this artifact?
- To model the flow of application data between different software systems.
- To document the physical database schemas and data storage locations.
- To define the key business information concepts and their relationships, independent of technology. (Correct answer)
- To track the lifecycle and versioning of all corporate documents.
Correct answer: To define the key business information concepts and their relationships, independent of technology.
An information map represents the key information concepts (e.g., Customer, Product, Order) that are important to the business and how they relate to each other. It provides a shared business vocabulary and is used to model the business, not a specific IT system.
Question 88: What is the role of encryption in data security?
- Deletes old files
- Speeds up retrieval
- Monitors network activity
- Converts data into unreadable format (Correct answer)
Correct answer: Converts data into unreadable format
Encryption is a fundamental security technique that transforms data into an unreadable, encoded format, known as ciphertext. This process makes the data unintelligible to unauthorized individuals, even if they gain access to it. The primary role of encryption is to protect the confidentiality of information, ensuring that only authorized parties with the correct decryption key can access and understand the original data.
Question 89: What is the purpose of a VLAN?
- Segment network traffic logically (Correct answer)
- Control data encryption
- Monitor printer usage
- Extend wireless range
Correct answer: Segment network traffic logically
A VLAN (Virtual Local Area Network) allows network administrators to logically segment a single physical network into multiple broadcast domains. This means devices on different VLANs cannot communicate directly without a router, even if they are connected to the same physical switch. VLANs improve network performance, security, and manageability by isolating traffic and reducing broadcast domains.
Question 90: What does DNS do in a network?
- Encrypts data
- Monitors traffic logs
- Resolves domain names to IP addresses (Correct answer)
- Assigns VLAN tags
Correct answer: Resolves domain names to IP addresses
DNS (Domain Name System) is a hierarchical and decentralized naming system for computers, services, or any resource connected to the Internet or a private network. Its primary function is to translate human-readable domain names (like www.example.com) into numerical IP addresses (like 192.0.2.1) that computers use to identify each other on a network. This translation is essential for web browsing and other internet services.
Question 91: What is a key benefit of business-IT alignment?
- More technical jargon in meetings.
- Reduced customer base.
- Improved business agility and performance. (Correct answer)
- Increased organizational silos.
Correct answer: Improved business agility and performance.
When IT strategy is closely aligned with business objectives, an organization can respond more quickly and effectively to market changes and new opportunities. This alignment enhances business agility by ensuring IT systems and processes support rapid adaptation and innovation. Ultimately, this leads to improved operational efficiency, better decision-making, and overall stronger business performance.
Question 92: In TOGAF, what is the primary purpose of the Architecture Vision document produced in Phase A?
- To define the governance mechanisms for architecture compliance
- To establish the migration roadmap from baseline to target state
- To document the detailed technical specifications for all systems
- To obtain approval to proceed and provide a high-level view of the target architecture (Correct answer)
Correct answer: To obtain approval to proceed and provide a high-level view of the target architecture
The Architecture Vision produced in Phase A provides a high-level summary of changes to the enterprise and serves as an agreement with stakeholders to proceed with the full architecture development.
Question 93: How can communication support IT-business alignment?
- By fostering collaboration and shared goals. (Correct answer)
- By limiting project scope.
- By eliminating business feedback.
- By using technical language only.
Correct answer: By fostering collaboration and shared goals.
Effective communication is vital for IT-business alignment as it breaks down silos and ensures a mutual understanding of objectives, challenges, and capabilities. By fostering open dialogue and collaboration, both IT and business stakeholders can work together towards shared strategic goals. This shared understanding prevents misunderstandings and ensures IT solutions truly meet business needs.
Question 94: Which standard format is used in data exchange between applications?
- ZIP
- JPEG
- JSON (Correct answer)
Correct answer: JSON
JSON (JavaScript Object Notation) is a lightweight, text-based data interchange format that is widely used for data exchange between applications, especially in web services. Its human-readable structure and ease of parsing by machines make it a popular choice for APIs and other integration scenarios. JSON's simplicity and flexibility have made it a de facto standard for modern application communication.
Question 95: An enterprise security architect is tasked with developing a comprehensive security architecture. A key requirement is that the entire architecture must be derived from and directly traceable to the organization's business objectives and risk tolerance. Which security architecture framework is specifically designed with this business-driven methodology at its core?
- TOGAF (The Open Group Architecture Framework)
- ITIL (Information Technology Infrastructure Library)
- Zachman Framework
- SABSA (Sherwood Applied Business Security Architecture) (Correct answer)
Correct answer: SABSA (Sherwood Applied Business Security Architecture)
SABSA is a methodology renowned for being business-driven. It starts with analyzing business requirements, goals, and risk appetite to create a security architecture where every control is traceable back to a business need. While TOGAF and Zachman are enterprise architecture frameworks, they are not as specifically focused on a business-risk-driven approach for security as SABSA is. ITIL is a framework for IT service management.
Question 96: What is a challenge of misalignment between IT and business?
- Inefficiencies and unmet business needs. (Correct answer)
- Increased project success.
- Optimized collaboration.
- Efficient IT budgeting.
Correct answer: Inefficiencies and unmet business needs.
When IT and business strategies are not aligned, IT projects may fail to address critical business requirements or may even hinder operational processes. This misalignment leads to significant inefficiencies, wasted resources, and a failure to leverage technology effectively to support business goals. Ultimately, it results in unmet business needs and a lack of strategic value from IT investments.
Question 97: Which of the following best describes the primary purpose of an N-Tier application architecture?
- To couple all application components tightly for higher performance.
- To enable direct communication between the user interface and the database.
- To consolidate all business logic into a single, monolithic service for easier management.
- To separate concerns by dividing the application into logical layers, such as presentation, business logic, and data access. (Correct answer)
Correct answer: To separate concerns by dividing the application into logical layers, such as presentation, business logic, and data access.
N-Tier architecture, often seen as a three-tier architecture (presentation, business/logic, and data), is designed to separate the application's responsibilities into distinct layers. [20, 21] This separation of concerns improves maintainability, scalability, and flexibility, as each layer can be developed and managed independently without affecting the others. [18, 20]
Question 98: An IT architect is developing a business technology strategy for a retail company planning to expand its e-commerce platform. Which of the following is the MOST critical first step in this process?
- Evaluating and selecting the most advanced and scalable e-commerce software.
- Establishing a technology governance framework and an Architecture Review Board.
- Conducting a detailed inventory of the current IT assets and infrastructure.
- Articulating the company's vision and strategic business goals for the next 3-5 years. (Correct answer)
Correct answer: Articulating the company's vision and strategic business goals for the next 3-5 years.
The foundation of any effective business technology strategy is its alignment with the overall business objectives. Before any technical evaluation or governance setup, the architect must understand what the business aims to achieve. Articulating the company vision and strategic goals ensures that all subsequent technology decisions directly support the desired business outcomes, such as market expansion, revenue growth, or enhanced customer experience.
Question 99: Which policy defines how users access resources in an organization?
- Access control policy (Correct answer)
- Backup policy
- Retention policy
- Email policy
Correct answer: Access control policy
An access control policy is a set of rules that dictates who can access specific resources (e.g., files, systems, applications) within an organization and what actions they are permitted to perform. It defines user roles, permissions, and authentication requirements, ensuring that only authorized individuals can interact with sensitive information and systems. This policy is crucial for maintaining data confidentiality, integrity, and availability.
Question 100: An enterprise is struggling with a legacy monolithic application where fixing bugs or adding new features has become excessively slow and expensive, often introducing new defects. This operational difficulty points to a significant degradation of which architectural quality attribute?
- Maintainability (Correct answer)
- Security
- Performance
- Portability
Correct answer: Maintainability
Maintainability is the quality attribute that describes the ease with which a system can be modified to correct faults, improve performance, or adapt to a changed environment. [4, 24] High costs, long timelines, and the introduction of new defects during modification are classic signs of poor maintainability.
IASA Certified IT Architect – Associate (CITA-A) Information Technology Architecture
The CITA-Associate certification validates knowledge of the Business Technology Architecture Body of Knowledge (BTABoK), assessing competency across IT architecture pillars including business strategy, infrastructure, security, application design, and quality attributes. It is administered by IASA Global (The Business Technology Architects Association).
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds