How to Prevent External Downloading in Google Drive DLP Rules?

Your organization has a data loss prevention (DLP) rule to detect and warn users about external sharing of sensitive files in Google Drive. You also want to prevent external users from downloading files with viewer permissions to their local machines. What should you do?

  1. Do nothing. View-only Drive files automatically prevent the user from downloading the files.
  2. Modify the existing DLP rule to Disable download, print, and copy for commenters and viewers. Source Reference Answer
  3. Create a new DLP rule by using the existing content detector conditions, but change the action for the new rule to Disable download, print, and copy for commenters and viewers.
  4. Create a new DLP rule and set the scope to the organizational unit or group that you want to restrict.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests your understanding of Google Workspace DLP rule structure and action scopes, with the common trap being the assumption that separate rules are needed for each restriction.

Configure Google Workspace DLP rules to restrict file actions like downloading, printing, and copying for viewers and commenters. The community consensus confirms that modifying an existing DLP rule is the correct approach rather than creating duplicate rules.

Option C is frequently chosen because test-takers incorrectly believe that adding a new restriction requires creating a completely new DLP rule instead of leveraging the multi-action capability of a single rule.

Community Discussion (3 comments)

apb98 👍 1 Selected: B
A single DLP rule can have multiple actions. By modifying the existing rule, you can add the new action to disable downloading, printing, and copying, without creating a separate rule.
dija123 👍 1 Selected: B
Agree with B
mostafa97 👍 2
“You also”. Key word so B is correct

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Google Workspace DLP rules support multiple actions within a single rule definition. By modifying the existing rule, administrators can add the disable download, print, and copy action alongside the original detection and warning action. This approach maintains a clean rule set and ensures consistent policy enforcement across all specified conditions without triggering redundant evaluations.

Why the Other Options Are Wrong

Option A is incorrect because view-only permissions in Google Drive do not inherently block downloads; viewers can still save or download files unless explicitly restricted by DLP or sharing settings. Option C unnecessarily duplicates the rule logic, which violates best practices for policy management and may cause unintended rule priority conflicts. Option D focuses on scoping rather than defining the required action, leaving the actual download prevention mechanism undefined.

Community Comment Notes

The top-voted explanation correctly highlights that a single DLP rule can accommodate multiple actions, making modification the optimal path. Users emphasize the keyword also as a direct indicator that the existing rule should be updated rather than replaced. Consensus strongly supports Option B due to its alignment with administrative efficiency and Google’s documented DLP architecture.

Official Reference

Exam Strategy

Always look for scope and action keywords that indicate whether a policy should be extended or created anew. When multiple restrictions apply to the same condition, prioritize modifying the existing rule over duplicating it to maintain exam accuracy and real-world admin efficiency.

Related Analysis

← Back to PWA Study Guide