Original question was how can netgroups be used to limit access for only
one group.
The answer is: They can't. As I thought. BUT there is a way around it.

The trick was to not think of giving access so much as denying it.

By changing the ownership of the directory to the excluded group and
then changing the permissions to 0705, I get the effect I needed.

