Courseiva

CISA Information System Auditing Process Practice Question

An IS auditor is testing the effectiveness of a control that involves a manual review of exception reports. The population of exceptions is 5,000 items. The auditor wants to achieve a 95% confidence level with a tolerable error rate of 2%. Which sampling method is MOST appropriate?

⚠ Common exam trap

CISA often tests the confusion between statistical and non-statistical sampling, and between attribute and variables sampling, causing candidates to choose stratified or systematic sampling when the question specifies confidence level and tolerable error rate for a control test.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Statistical attribute sampling

Statistical attribute sampling is the most appropriate method when the auditor wants to achieve a specified confidence level and tolerable error rate for a control that has a binary outcome (exception or no exception). It allows the auditor to project the exception rate to the population and conclude whether the control is operating effectively within the tolerable deviation rate.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Systematic sampling

    Why it's wrong here

    Systematic sampling picks every nth item from a sequential list; without a random start and shuffled population it cannot deliver the stated 95% confidence and 2% tolerable error rate. It is tempting for its speed on ordered populations, and would suit evenly distributed, non-patterned data.

  • ✗

    Judgmental sampling

    Why it's wrong here

    Judgmental sampling selects items by auditor discretion, which cannot mathematically support a 95% confidence level or a 2% tolerable error rate. It is tempting because it is quick and targets high-risk areas, and would be correct for exploratory work where statistical projection is not required.

  • ✗

    Stratified sampling

    Why it's wrong here

    Stratified sampling divides the population into subgroups to ensure representation across distinct strata, but the 5,000 exception reports are homogeneous items with no natural grouping relevant to the control’s manual review. It is tempting because stratification reduces variance in heterogeneous populations, such as when exceptions differ by region or severity, where it would correctly isolate high-risk subsets for targeted testing.

  • ✓

    Statistical attribute sampling

    Why this is correct

    Statistical attribute sampling quantifies the exception rate against a defined confidence level and tolerable deviation rate, letting the auditor conclude on the 5,000-item population with measurable precision. Judgemental or block methods cannot support the stated 95% confidence and 2% tolerable error.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.