hello
I think the only way is to create two different policies :
1 with response rules which block action for g1, g2, and g3
1 with response rules which not block action for g4 (so you will have monitoring for this group)
And if one day symantec allow to use logical OR in policy definition (and in profile definition will be helpful too) you will be able to merge these two policies into one. I had the same issue and didnt find any other way to do it.