IS 監査人は、アプリケーションのシステム ログに記録されたアクセスのサンプルを分析しています。監査人は、例外が 1 つ見つかった場合に徹底的な調査を開始する予定です。どのサンプリング方法が適切でしょうか。
正解:A
Discovery sampling is an appropriate sampling method for an IS auditor who intends to launch an intensive investigation if one exception is found. Discovery sampling is a type of attribute sampling that determines the sample size based on an acceptable risk of not finding at least one occurrence of an attribute when a given rate of occurrence exists in a population. Discovery sampling can be used by an IS auditor who wants to detect fraud or errors that have a low probability but high impact on an audit objective. The other options are not appropriate sampling methods for this purpose, as they may involve judgmental sampling, variable sampling, or stratified sampling. References:
* CISA Review Manual (Digital Version), Chapter 2, Section 2.31
* CISA Review Questions, Answers & Explanations Database, Question ID 230