ASP System Safety Engineering and Analysis — Questions and Answers
Question 1: A Preliminary Hazard Analysis (PHA) is most appropriately conducted:
- Early in the conceptual or design phase, before detailed designs are finalized (Correct answer)
- After a serious incident has occurred to identify root causes
- During final product testing before release to market
- As an annual review of existing hazard control measures
Correct answer: Early in the conceptual or design phase, before detailed designs are finalized
PHA is specifically designed for use in the early design or conceptual phase when detailed information is limited. Its purpose is to identify major hazards and define safety requirements before costly design commitments are made. Conducting it after the design is finalized limits the ability to make fundamental changes.
Question 2: In a Fault Tree Analysis (FTA), a 'basic event' symbol (circle) represents:
- A primary failure that requires no further development and has an assigned probability (Correct answer)
- An event that has not been fully developed due to lack of information
- A gate that combines multiple input events
- The top-level undesired event being analyzed
Correct answer: A primary failure that requires no further development and has an assigned probability
In FTA, the circle (basic event) is a leaf node representing an elementary failure for which a probability can be directly assigned from historical data or engineering judgment. It requires no further decomposition. The diamond represents an undeveloped event, rectangles represent developed events (gates), and the top event is the undesired outcome being studied.
Question 3: Which system safety analysis technique uses a matrix or table to systematically evaluate what happens when each component fails in different modes (e.g., fails open, fails closed, fails to operate)?
- Failure Mode and Effects Analysis (FMEA) (Correct answer)
- Fault Tree Analysis (FTA)
- Hazard and Operability Study (HAZOP)
- Change Analysis
Correct answer: Failure Mode and Effects Analysis (FMEA)
FMEA systematically examines each component, identifies all potential failure modes (how it could fail), and evaluates the effects of each failure on the overall system. FTA works top-down from an undesired event. HAZOP uses guide words applied to process parameters. Change analysis compares a changed system to a baseline.
Question 4: A HAZOP study uses 'guide words' applied to process parameters. Which guide word indicates that a parameter (such as flow) is entirely absent?
- NO / NONE (Correct answer)
- MORE
- LESS
- REVERSE
Correct answer: NO / NONE
In HAZOP, the guide word NO/NONE means the intended parameter (e.g., flow, pressure, temperature) is completely absent—no flow where flow was intended. MORE means a quantitative increase, LESS means a quantitative decrease, and REVERSE means the parameter acts in the opposite direction (e.g., backflow). HAZOP is especially used in process industries.
Question 5: The minimum cut set in a Fault Tree Analysis represents:
- The smallest combination of basic event failures that is sufficient to cause the top event (Correct answer)
- The most cost-effective set of corrective actions to prevent the top event
- The minimum number of safety controls required by regulation
- The baseline failure rate below which no further improvement is possible
Correct answer: The smallest combination of basic event failures that is sufficient to cause the top event
A minimum cut set is the smallest group of basic events whose simultaneous occurrence guarantees the top (undesired) event occurs. Identifying minimum cut sets reveals critical failure combinations and single points of failure (cut sets of size 1). Eliminating or protecting against minimum cut sets is the most efficient way to reduce top-event probability.
Question 6: In system safety, the concept of 'defense in depth' is best described as:
- Implementing multiple independent layers of protection so that no single failure leads to a catastrophic outcome (Correct answer)
- Conducting thorough documentation of all safety procedures as the primary defense against accidents
- Using the most expensive available engineering control as the primary safeguard
- Assigning responsibility for safety to the deepest level of the organizational hierarchy
Correct answer: Implementing multiple independent layers of protection so that no single failure leads to a catastrophic outcome
Defense in depth (also called the 'Swiss cheese model' concept) relies on multiple independent barriers so that even if one layer fails (a 'hole in the cheese'), other layers prevent the hazard from reaching the target. It is a foundational system safety principle used in nuclear, aviation, chemical process, and general industry applications.
A Preliminary Hazard Analysis (PHA) is most appropriately conducted: