Professional Documents
Culture Documents
Jose Ignacio Gonzalez Rodriguez-331064371-Online - TÜV SÜD - Functional Safety Certified Professional in Accordance With EN 5012X
Jose Ignacio Gonzalez Rodriguez-331064371-Online - TÜV SÜD - Functional Safety Certified Professional in Accordance With EN 5012X
Report Summary
Name : Jose Ignacio Gonzalez Rodriguez
Your Score : 44 out of 140 (31.43%)
Correct Answers : 44 Questions
Incorrect Answers : 16 Questions
Unanswered : 0 Questions
Required Passing Grade (%) : 51%
Time Taken : 04 hrs
Date : Jan 16, 2024
Email : jigonzalez.fpe@gmail.com
Phone No. : +97156 9769968
Training Start Date : 23/11/2023
Training End Date : 26/11/2023
Your Answers
Q2) The maintenance carried out after fault recognition and intended to put product
into a state of working condition is called as:
A. Preventive maintenance
B. Maintenance management
C. Corrective maintenance (Your Answer)(Correct)
D. Condition based maintenance
Q3) Reliability of two subsystems 1& 2 are R1=0.99, R2= 0.95, what is unreliability of
subsystem 2, Q(t)=?
A. Q(t)=0.1
B. Q(t)=0.05 (Your Answer)(Correct)
C. Q(t)=0.01
D. Q(t)=0.0595
Q4) Which phase of Life cycle as per 50126 recommends to perform Preliminary RAM
analysis
A. Concept Phase
B. System Definition Phase (Your Answer)(Correct)
C. Design phase
D. Verification and Validation
Q15) About Life Cycle Cost (LCC) – Mark the statement which is not true
A. Assessing total cost of the product over its total span of the life of the product
B. Helpful in making a logical business decision
C. Customers can evaluate and compare alternative products
D. LCC always provides solutions to RAMS. (Your Answer)(Correct)
Q17) By the end of System acceptance phase Assessment RAM validation should be
completed
A. True (Correct)
B. False (Your Answer)(Incorrect)
Q19) Safety case is necessary to justify that the system as designed and independent
of application, meets safety requirements
A. True (Your Answer)(Correct)
B. False
Q27) In the “V”- Model testing of the product is planned in parallel with a corresponding
phase of development in V-Model
A. True (Correct)
B. False (Your Answer)(Incorrect)
Q29) Hazard log to be established and maintained throughout the life cycle of a product
if it is
A. SIL 1 and SIL 2
B. SIL 3 and SIL 4
C. SIL1, SIL 2, SIL 3 and SIL4 (Correct)
D. None of the above (Your Answer)(Incorrect)
Q34) Which one of the following statement not to be considered for functional safety
analysis?
A. Entrance of a train on a track when the signal was not given
B. Over speed of the train could not be controlled
C. Pedestrian slips and falls on the track while crossing the track (Your Answer)(Correct)
D. Passenger fall due to metro door opening during the run.
Q35) The failure mode failure rate of a Relay in its dangerous mode is 0.5 x 10^(-9).
The dangerous mode of failure is detected with diagnostic coverage 80%. The
dangerous failure detected is
A. 0.10 x 10^(-9)
B. 0.40 x 10^(-9)\ (Your Answer)(Correct)
C. 0.001x 10^(-9)
D. 0.04 x 10^(-9)
Q38) The Safety Assessor for Safety verification and validation can be
A. Part of customer organization or Supplier organization
B. The safety authority to approve the choice of the assessor (Correct)
C. The safety assessor shall report directly to safety authority
D. Independent from project team (Your Answer)(Incorrect)
Q39) If the tolerable hazard risk of a hazard is between 10^(-7) and 10 ^ (-6) then it is
A. SIL 1
B. SIL 2 (Your Answer)(Correct)
C. SIL 3
D. SIL 4
Q43) The safety analysis normally used in proving the RAMS requirements are
A. Reliability prediction
B. FTA, FMECA and Root cause analysis (Your Answer)(Incorrect)
C. Failure mode and Effect Diagnostic Analysis
D. All of the above (Correct)
Q47) MTTF is the metric for Reliability and MTTR is the metric for Maintainability
A. True (Your Answer)(Correct)
B. False
Q52) For a given railway system Availability requirement is 0.99, after analysis it is
found MTBF =24000 KMs, what should be MTTR so that it can meet the
availability requirement, train runs 120 Kms in a day.
A. MTTR = 1 day
B. MTTR=2 days (Your Answer)(Correct)
C. MTTR=2 Hours
D. MTTR=1 Hour
Q56) Any modification in the design demands a relook into hazard log
A. True (Your Answer)(Correct)
B. False
Q61) Three functional configuration options which are basically comparable in cost are
being considered for a particular segment of a system. These options are:
Your answer
Option III. R=0.99
Sl. Elemen
No.
1 Pressure
Transmitter
2 Isolator
3 Trip amplifie
configuration
4 Isolator
5 Actuator
b.
R1=0.9907; MTBF1=2560
R2=0.9716; MTBF2=833
R3=0.8096; MTBF=114
R4=0.9997; MTBF=83333
R5=0.7866; MTBF=100
c. Rs=0.730
d. As= 0.9892
Q63) Identify level of independence required for a SIL 2 product and list down all HR
activities in Design & Development phases
Your answer
A. DES independent of VER or VAL, both reporting to the PM and can be of the same
organization. ASSR totally independent and different organization.
B. Structured Design and Modularisation
Q64) Observe the rolling stock picture and their parts, prepare a hazard log, hazards
can be written from your experience, engineering judgement and imaginative, but
follow proper template
Your answer
One line provided for illustration
Unmitigated Mitigated
Subsys. Hazard Cause Conseq. Freq. Risk Risk Mit. Conseq. Freq. Risk Clos.
Descriptive Example
- Subsystem: Floor
- Hazard: Seat materials not compliant with standards for ignition resistance, flame spread and
smoke and toxicity generation, when exposed to a fire. In case of a fire on board, the floor can
contribute to increase the fire size, and spread it to other seats, while generating smoke and toxic
gases that can cause casualties.
- Cause: Overheating of uninsulated electrical equipment, arsonism.
- Unmitigated conseq: Catastrophic
- " freq.: Occassional
- " risk: Intolerable
- Risk Mitigation: Using seat manufacturing materials and systems compliant with EN 45545 for
the required hazard level.
- Mitig. conseq: Marginal
- Mitig. freq: Improbable
- Mitig. risk: Negligible
- Clos.: "Closed" (Negligible is acceptable)
Your answer
A: P= 3.43E-6
B: 8. Each one can be a single point failure (i.e., OR gate).
C: Random failures can be due to human error or technical failures (e.g., failures of hardware,
software, etc.). If we consider this, we might assume that environmental conditions (outside of the
design boundaries) is he only cause that can be random. The SIL level for 3.5E-7 would be SIL 2,
compared to the overall SIL (3.43E-6) which will be SIL 1.
Q67) Given the table below on possible hazard triggering conditions while the train is
moving. Map it to the appropriate consequence / Consequences by marking (x) in
the appropriate cell Hazard ID Hazard Triggering condition Consequence Collision
Derailment Death/Injury Fire/Smoke Electrocution Other HAZ-1 Objects on the
Guideway HAZ-2 People Trespassing HAZ-3 Extreme weather condition (Ice,
Extreme cold, Heavy rainfall, Excessive Foliage) HAZ-3 Train movement with
doors open HAZ-4 Failure or distortion of guideway, sleepers or ballast slip HAZ-5
Reduced brake performance HAZ-6 Train doors trap person or object and train
moves off whilst person still trapped HAZ-7 Person attempts to open a door and
jump out while the train is moving HAZ-8 Overcrowding of platforms in
underground stations HAZ-9 Pantograph suddenly lowered and lost the contact
with catenary w HAZ-10 Emergency brake failure HAZ-11 Train is automatically
moved to an area (e.g. station or tunnel where there is a fire or other HAZ-12
Signaling system failure to detect the presence of another train in the same track
where the train is running
Your answer
Note: The consequence initials will be used for simplicity.
Your answer
This topic was not given in the program...
Q70) Carry out FMECA analysis for the components present in the system described in
question 1 for the components present in the system.
Your answer
Not sure what the components were for "question 1" (I presume that it will be the same as the
ones represented above. I'll develop a simple example of FMECA for rolling stock - RSK -
(critical) failure:
A table will be created with these headings (simplified), followed by an example (e.g., RSK brake
cable failure).
- Function: Brake cable sends the signal from the train desk to brake system.
- Fail. Mode: Brake cable breaks (no replaced iin the preventive maintenance, due to
maintenance human error).
- Fail. Effects: The train driver cannot stop the train.
- Effects Severity: Catastrophic (a rating number will be assigned; e.g., 9/10)
- Fail. Cause: Cable not replaced during preventive maintenance, due to a human error
(maintenance crew forgot to replace the cable). Aging of the cable cause its breakage.
- Fail. Cause Probability: Probable (Rating assigned, like the above; e.g., 7/10)
- Design Controls: Redundant cable, detection of broken cable.
- Detection: High chance of cable breackage detection (ranking e.g., 9/10)
- Risk Priority Number: A risk priority number will be assigned relative to other risks.