How to Restrict Document Access by Company in Google Workspace?
You work at a large global holding firm with multiple companies that are united under one Google Workspace deployment. You must ensure that employees can only access documents at the company in which they are employed. What should you do?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests your ability to isolate data across business units within a single tenant, with the common trap being overly broad sharing blocks that hinder legitimate cross-company operations.
Learn how to enforce strict document isolation between subsidiary companies in a unified Google Workspace deployment. The community strongly endorses using organizational trust rules to maintain secure, compartmentalized data access.
Option A is frequently chosen because blocking external sharing seems logical, but it incorrectly restricts all outside collaboration needed for auditors, partners, or vendors rather than isolating internal company boundaries.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Setting up Google Drive trust rules allows administrators to precisely control sharing permissions based on corporate boundaries. This ensures that users within one subsidiary cannot view or share files with another, maintaining strict data segregation without breaking core Workspace functionality. By targeting access at the organizational level, you align security policies with your company’s legal and operational structure.Why the Other Options Are Wrong
Option A blocks all external sharing globally, which would prevent necessary interactions with external auditors, clients, or third-party services. Option B disables file sharing entirely across the organization, crippling productivity and violating basic collaboration requirements. Option C focuses on DLP, which scans content for sensitive data patterns rather than enforcing structural access controls tied to company entities.Community Comment Notes
Exam candidates consistently highlight that while terminology may vary slightly across updates, trust rules remain the definitive mechanism for company-level isolation. One contributor notes that DLP is content-specific and not designed for OU-based access management, reinforcing why administrative grouping is superior. Another user confirms that broad sharing blocks create unnecessary compliance roadblocks for routine business functions.Official Reference
Exam Strategy
Always map administrative controls to organizational boundaries first before applying blanket security policies. When questions mention multi-company structures under a single tenant, prioritize OU-based or trust rule configurations over global sharing restrictions to balance security with operational flexibility.