Select Exam:
ISACA CISA 2024 Blueprint 10-Question Diagnostic
~10 minutes· Question 1 of 10· 12-Week Plan PDF
CISA1-CTopic: Findings and Recommendations

During an audit of a financial services firm, an IS auditor discovers that the quarterly user access review for the core trading application has not been performed for the last two quarters. This control is documented as critical for preventing unauthorized access. What should be the auditor's FIRST action?