Courseiva
mediumMultiple Select

CISA Practice Question: An IS auditor is selecting an appropriate audit…

An IS auditor is selecting an appropriate audit sample. Which THREE of the following are factors that affect the sample size?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Tolerable error rate

Tolerable error rate (A) is correct because it defines the maximum deviation from the control that the auditor is willing to accept while still relying on the control; a lower tolerable rate requires a larger sample to detect deviations. Confidence level (B) is correct because it reflects how certain the auditor wants to be that the sample result is representative of the population, and higher confidence directly increases the required sample size. Expected error rate (D) is correct because the auditor's estimate of the deviation rate in the population drives sample size upward as the expected rate approaches the tolerable rate. Sampling interval (C) is not a determinant of sample size; it is derived from the sample size and population size when using systematic selection. Population standard deviation (E) applies to variables sampling for monetary amounts, not to attribute sampling for control deviations, so it is not a general factor here.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Tolerable error rate

    Why this is correct

    Tolerable error rate directly drives sample size: the lower the rate the auditor will accept without extending testing, the larger the sample must be to detect deviations. It is one of the three inputs, alongside expected error rate and confidence level, that determine how many items are selected.

  • ✓

    Confidence level

    Why this is correct

    Confidence level directly determines sample size: a higher required confidence that the sample reflects the population demands a larger sample. It is one of the three primary statistical inputs, alongside tolerable error and expected error rate, that auditors use to calculate an appropriate sample size.

  • ✗

    Sampling interval

    Why it's wrong here

    Sampling interval determines which items are selected, not how many; it is the spacing used in systematic selection. It becomes relevant only after sample size is fixed, when planning selection. Factors affecting size include population size, confidence level, tolerable error and expected error rate.

  • ✓

    Expected error rate

    Why this is correct

    Expected error rate directly affects sample size: the more errors anticipated in the population, the larger the sample needed to obtain a reliable conclusion. Auditors increase sample size when a higher deviation rate is expected, making this one of the three primary factors influencing sampling.

  • ✗

    Population standard deviation

    Why it's wrong here

    Standard deviation is a variable-sampling parameter used in monetary-unit or classical variables sampling to project misstatement amounts, not an attribute-sampling input. For attribute sampling, size derives from confidence level, tolerable deviation rate and expected deviation rate. The stem's generic audit sampling assumes attribute testing.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.