Question 1
You have a multi-agent GitHub Actions workflow that uploads review artifacts for each run.
You discover that some workflow run artifacts are being deleted manually.
You need to use your organization's audit log data to identify which user deleted the artifacts.
Which audit log search filter should you use?
The filter action:artifact.destroy selects the audit event associated with manual deletion of a workflow artifact. It directly targets the activity described in the scenario, allowing the investigator to examine the recorded actor and associated event details.
A repository filter narrows the search to a particular repository but does not distinguish artifact deletion from other recorded operations. It can usefully accompany the action filter when investigating a specific project. A workflow-run action concerns workflow execution rather than the manual removal of its stored artifacts. The generic operation:remove option does not select the documented artifact deletion event.
The investigation should correlate the deletion event with its timestamp and repository information, then inspect the actor recorded for that event. This identifies the account associated with the action; additional context may be needed when an application or automated identity performed it.
Artifact retention and audit logging serve separate purposes. Retention controls how long outputs are normally preserved, while the audit log records relevant administrative and user activity. Searching the audit log does not restore deleted content.
Study-guide topics: accountability, evidence preservation, actor attribution, and audit trails. Reference: GitHub---Organization audit log events.