Courseiva

CISA Information System Auditing Process Practice Question

During an audit, the auditor uses a sampling method where the population is divided into subgroups, and samples are selected from each subgroup. This method is known as:

⚠ Common exam trap

CISA often tests the distinction between stratified and systematic sampling — candidates confuse 'dividing into subgroups' with 'selecting every nth item', but only stratified sampling involves population subdivision.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Stratified sampling

Stratified sampling divides the population into homogeneous subgroups (strata) — such as by department, transaction type, or risk level — and then draws samples from each stratum, often proportionally or with higher sampling in high-risk strata. This guarantees representation of every subgroup and reduces sampling risk compared to simple random sampling. It is the standard ISACA-recommended technique when the population is heterogeneous and the auditor needs coverage across distinct categories.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Systematic sampling

    Why it's wrong here

    Systematic sampling picks every nth item from a single ordered list, using one fixed interval rather than dividing the population into subgroups. It is tempting because it is a probability method giving even coverage, and would be correct where a sequential list exists and a constant sampling interval is applied throughout.

  • ✗

    Judgmental sampling

    Why it's wrong here

    Judgmental sampling relies on the auditor's professional discretion to pick items, with no subgroup division or statistical basis. It is tempting because it is efficient for targeted testing of high-risk or unusual items, and would be correct where the auditor deliberately selects specific transactions based on experience.

  • ✗

    Random sampling

    Why it's wrong here

    Random sampling draws items from the entire population without first partitioning it into subgroups, so no stratified structure exists. It is tempting because it is the classic probability method underpinning statistical inference, and would be correct where every item has an equal chance of selection across the whole population.

  • ✓

    Stratified sampling

    Why this is correct

    Stratified sampling divides the population into distinct subgroups (strata) and draws samples from each, directly matching the stem's description. Unlike simple random or systematic sampling, it guarantees representation across every subgroup, which suits audit populations with heterogeneous characteristics where each stratum warrants coverage.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.