Your organization wants to monitor and audit IAM permission changes in real time. Which type of Cloud Audit Log is enabled by default and cannot be disabled?
Admin Activity logs are enabled by default and cannot be disabled. They log API calls and administrative actions that modify the configuration or metadata of resources.
Why this answer
Admin Activity audit logs record API calls and administrative actions that modify the configuration or metadata of resources. They are enabled by default and cannot be disabled, making them ideal for monitoring IAM permission changes.