Hello cwen
Welcome to vSphere and Communities.
There are a number of methods of preventing different types of access but what needs to be applied (and where) to harden the VMs depends on a number of things - e.g. blocking ALL file transfer should just be a case of configuring firewall/blocking ports on the Guest-OS level but settings such as disabling copy+paste are at the VM level using the isolation configurations:
Security Considerations for Configuring VMware Tools
Disabling shared folder with ESXi host is perhaps another consideration (depending on what you are trying to achieve):
Disable VMware Shared Folders Sharing Host Files to the Virtual Machine
Bob