Which two GitHub Enterprise capabilities most directly help an organization produce ongoing compliance evidence for access and configuration changes? (Choose two.)
Select all correct answers, then click Submit.
Short Explanation and Infographic
Strong ongoing compliance evidence pairs enterprise audit logs of who changed access and settings with Security Overview for vulnerability posture. Never weaken auth or publish root passwords as an audit shortcut.
Full explanation below image
Full Explanation
Auditors typically ask who had access, who changed privileged settings, and what security findings existed during a control period. Enterprise audit logs—retained, exported, or streamed—provide chronological administrative evidence. Security Overview and enterprise security alert surfaces summarize code scanning, secret scanning, and Dependabot posture for risk reporting. Disabling authentication or publishing privileged credentials is never an acceptable evidence strategy. Organizations should define retention periods aligned to regulatory needs, restrict who can read full audit data, and automate periodic reports rather than scrambling at audit time. Combining identity provider logs with GitHub audit events strengthens the end-to-end access narrative.