← All SIL Flashcard Decks

Hardware Architecture & Fault Tolerance Flashcards

7 cards from real SIL practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Hardware Architecture & Fault Tolerance flashcards as text
  1. Per IEC 61508-2, what minimum Hardware Fault Tolerance is required for a Type B subsystem with SFF between 60% and 90% targeting SIL 3?

    Answer: HFT = 2

    IEC 61508-2 Table 3 specifies that a Type B subsystem with SFF in the 60–90% range requires HFT = 2 to satisfy SIL 3 architectural constraints.

  2. What is a 'common cause failure' (CCF) in a redundant safety system?

    Answer: A failure event that causes multiple redundant channels to fail simultaneously from the same root cause

    CCF defeats redundancy by propagating a single failure mechanism — such as a design flaw, shared environment, or installation error — across multiple channels at once.

  3. Which statement best describes a 'dangerous undetected' (DU) failure?

    Answer: A failure that disables the safety function without being identified by online diagnostics

    DU failures are the most critical category: they leave the safety system unable to respond to a demand, yet remain hidden until a proof test or an actual demand reveals them.

  4. How does increasing diagnostic coverage (DC) affect the average Probability of Failure on Demand (PFD)?

    Answer: Higher DC reduces the rate of dangerous undetected failures, thereby lowering the system PFD

    Higher DC converts more dangerous failures into detected failures, reducing λDU and thus lowering the PFD calculated over the proof test interval.

  5. In reliability engineering for safety systems, what does 'derating' mean?

    Answer: Operating components below their rated electrical, thermal, or mechanical limits to improve reliability

    Derating involves using a component at, for example, 50% of its rated power or voltage, which reduces internal stress and significantly improves long-term reliability.

  6. What is the Hardware Fault Tolerance of a 2oo2 (2-out-of-2) voting architecture?

    Answer: HFT = 0

    In 2oo2, both channels must function for the safety action to occur; a single channel failure defeats the safety function, so HFT = 0.

  7. For a SIL 2 safety function that must minimize spurious trips in a continuous process, which voting architecture is most appropriate?

    Answer: 2oo3

    2oo3 achieves HFT = 1 (satisfying SIL 2 architectural requirements) and requires two channels to agree before activating, reducing spurious trips compared to 1oo2.