mediumMultiple Select
CISA Practice Question: An IS auditor is selecting an appropriate audit…
An IS auditor is selecting an appropriate audit sample. Which THREE of the following are factors that affect the sample size?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Tolerable error rate
Tolerable error rate (A) is correct because it defines the maximum deviation from the control that the auditor is willing to accept while still relying on the control; a lower tolerable rate requires a larger sample to detect deviations. Confidence level (B) is correct because it reflects how certain the auditor wants to be that the sample result is representative of the population, and higher confidence directly increases the required sample size. Expected error rate (D) is correct because the auditor's estimate of the deviation rate in the population drives sample size upward as the expected rate approaches the tolerable rate. Sampling interval (C) is not a determinant of sample size; it is derived from the sample size and population size when using systematic selection. Population standard deviation (E) applies to variables sampling for monetary amounts, not to attribute sampling for control deviations, so it is not a general factor here.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Tolerable error rate
Why this is correct
Tolerable error rate directly drives sample size: the lower the rate the auditor will accept without extending testing, the larger the sample must be to detect deviations. It is one of the three inputs, alongside expected error rate and confidence level, that determine how many items are selected.
- ✓
Confidence level
Why this is correct
Confidence level directly determines sample size: a higher required confidence that the sample reflects the population demands a larger sample. It is one of the three primary statistical inputs, alongside tolerable error and expected error rate, that auditors use to calculate an appropriate sample size.
- ✗
Sampling interval
Why it's wrong here
Sampling interval determines which items are selected, not how many; it is the spacing used in systematic selection. It becomes relevant only after sample size is fixed, when planning selection. Factors affecting size include population size, confidence level, tolerable error and expected error rate.
- ✓
Expected error rate
Why this is correct
Expected error rate directly affects sample size: the more errors anticipated in the population, the larger the sample needed to obtain a reliable conclusion. Auditors increase sample size when a higher deviation rate is expected, making this one of the three primary factors influencing sampling.
- ✗
Population standard deviation
Why it's wrong here
Standard deviation is a variable-sampling parameter used in monetary-unit or classical variables sampling to project misstatement amounts, not an attribute-sampling input. For attribute sampling, size derives from confidence level, tolerable deviation rate and expected deviation rate. The stem's generic audit sampling assumes attribute testing.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.