CISA Information System Auditing Process Practice Question
Which TWO of the following are types of statistical sampling methods? (Select TWO.)
⚠ Common exam trap
CISA often tests whether candidates can distinguish statistical from non-statistical sampling; the trap is assuming that any structured method (like systematic) is non-statistical, or that judgmental sampling is statistical because it is 'planned.'
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Stratified sampling
Stratified sampling (B) is a statistical sampling method in which the population is divided into homogeneous subgroups (strata) and random samples are drawn from each stratum, ensuring representation across defined characteristics. Systematic sampling (C) is also statistical: it selects every nth item from a population after a random starting point, applying a measurable, probability-based selection interval. Both are probability-based techniques because each item has a known, non-zero chance of selection, which supports statistical inference. By contrast, block sampling (A) is a non-statistical approach that selects contiguous groups or clusters of items, haphazard sampling (D) relies on convenience with no defined selection probability, and judgmental sampling (E) depends on the auditor's subjective judgment, so none of these are statistical sampling methods.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Block sampling
Why it's wrong here
Block sampling selects one contiguous block of items from the population, so it is a non-statistical method because not every item has a known chance of selection. It is tempting because it is efficient for sequentially ordered records, and it would be valid where the auditor only needs a quick scan of a transaction stream.
- ✓
Stratified sampling
Why this is correct
Stratified sampling divides the population into homogeneous subgroups (strata) before random selection from each, satisfying the stem's requirement for a statistical sampling method. Unlike judgemental or haphazard approaches, it uses probability theory, letting auditors quantify sampling risk and project results to the full population.
- ✓
Systematic sampling
Why this is correct
Systematic sampling selects every nth item from a population after a random start, making it a statistical (probability) method because each item has a known, non-zero selection chance. This satisfies the stem's requirement for statistical sampling types, unlike judgemental or block selection, which lack measurable selection probabilities.
- ✗
Haphazard sampling
Why it's wrong here
Haphazard sampling picks items arbitrarily without random selection, so each population item lacks a calculable selection probability, which statistical sampling requires. It appeals because it is quick and needs no random-number tool, and it would suit preliminary or low-risk testing where formal statistical inference is not intended.
- ✗
Judgmental sampling
Why it's wrong here
Judgmental sampling relies on the auditor's professional judgement to choose items, so selection probability cannot be quantified and sampling risk cannot be measured. It is tempting because it targets high-risk or unusual items efficiently, and it would be correct for focused testing of specific concerns rather than projecting results to the population.
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.