How to Efficiently Apply an Existing DLP Policy to a Finance Shared Drive?

You have implemented a data loss prevention (DLP) policy for a specific finance organizational unit. You want to apply the same security policy to a shared drive owned by the finance department in the most efficient manner. What should you do?

  1. In the Admin console sharing settings, select the finance organizational unit and deselect Allow users outside the domain to access files in shared drives.
  2. Assign the Shared Drive to the finance organizational unit. Source Reference Answer
  3. Create a new DLP policy for shared drive users.
  4. Change the scope of the policy to apply to all in the domain.

Community Votes

B
75%
C
25%

75% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests your understanding of Google Workspace policy inheritance via OU assignment, with the common trap being the assumption that Shared Drives require entirely separate DLP configurations.

Learn how to efficiently extend organizational unit (OU) Data Loss Prevention policies to Google Workspace Shared Drives. The community consensus confirms that assigning the shared drive directly to the target OU automatically inherits existing security rules without manual duplication.

Option C is frequently chosen due to the misconception that Shared Drives operate outside OU boundaries; however, creating a duplicate policy increases administrative overhead and violates the efficiency requirement.

Community Discussion (5 comments)

ptsironis 👍 2 Selected: B
By assigning the shared drive to the finance organizational unit, any DLP policies applied to that OU will automatically apply to the shared drive. This ensures consistency in security settings and simplifies management.
3fd692e 👍 2 Selected: B
The phrasing askes to complete the task in the most efficient manner possible. Creating a new DLP rule is more time consuming than simply assigning the shared drive to the OU where the DLP rule already exists. Correct answer is B.
csavar 👍 1
i think only assigning the drive is not enough
apb98 👍 2 Selected: B
My bad, it's B. If you want the data protection rules set for an organizational unit to apply to certain shared drives. Assign the shared drives to that organizational unit so that the same data protection rules apply.
apb98 👍 2 Selected: C
Since Shared Drives are not directly tied to OUs, you need to create and apply a separate DLP policy that targets the Shared Drives.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Assigning a Shared Drive to an Organizational Unit (OU) in Google Workspace allows it to inherit all security, compliance, and DLP policies scoped to that OU. This mechanism eliminates the need for redundant policy creation and ensures consistent enforcement across departmental resources. By linking the drive to the finance OU, administrators achieve immediate policy alignment with minimal configuration steps.

Why the Other Options Are Wrong

Option A modifies external sharing restrictions rather than applying internal DLP rules, making it irrelevant to data loss prevention. Option C contradicts the prompt’s requirement for efficiency, as manually crafting a new policy duplicates effort and increases maintenance complexity. Option D overextends the scope to the entire domain, which breaches the principle of least privilege and exposes non-finance data to unnecessary restrictions.

Community Comment Notes

Candidates consistently validate Option B through practical experience, noting that OU assignment triggers automatic policy inheritance for Shared Drives [1][2]. Several users initially selected C but corrected themselves after recognizing that Shared Drives fully support OU-based scoping in modern Workspace configurations [3][4]. The discussion highlights that efficiency and centralized management are key grading criteria for this scenario.

Official Reference

Exam Strategy

When exam questions emphasize "efficiency" or "automate," prioritize inheritance and grouping mechanisms over manual recreation. Always map resource types like Shared Drives to their native administrative containers like OUs before considering standalone policy creation.

Related Analysis

← Back to PWA Study Guide