Associate Cloud Workspace Administrator · Free Practice Question Medium
Question 4
Your organization has recently migrated to Google Workspace and you are tasked with setting up Google Drive for sensitive project files. The goal is to restrict access to files only to specific departments, while also allowing project managers to control sharing settings within their own teams. Which of the following approaches should you take to accomplish this?
-
A
Implement Google Drive API to automatically adjust sharing settings based on group membership.
-
B
Set Drive sharing settings to "Anyone in the organization" and ask project managers to manually adjust permissions for their teams.
-
C
Create Google Groups for each department, then use these groups to set sharing permissions for Drive folders.
-
D
Use the Admin console to create an Organizational Unit (OU) for each department and set restrictive Drive sharing settings at the OU level.
Reveal correct answer
Correct answer: D
A. Implementing the Google Drive API to automatically adjust sharing settings based on group membership may provide automation capabilities, but it may not offer the level of control needed to restrict access to specific departments. This approach may also introduce complexity and potential errors in managing sharing settings for sensitive project files.
B. Setting Drive sharing settings to "Anyone in the organization" and relying on project managers to manually adjust permissions for their teams can lead to potential security risks. This approach lacks centralized control and may result in inconsistent sharing settings across different teams, potentially exposing sensitive project files to unauthorized users.
C. Creating Google Groups for each department and using these groups to set sharing permissions for Drive folders can help in organizing users based on departments. However, this approach may lack the granularity needed to set specific sharing settings for individual files or folders within the Drive. It may also require manual management of group memberships for access control, which can be cumbersome and error-prone.
D. Using the Admin console to create an Organizational Unit (OU) for each department allows for granular control over Drive sharing settings at the department level. This approach ensures that access to sensitive project files is restricted to specific departments, while still allowing project managers to manage sharing settings within their own teams.
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
