Systemd Mitigation

What is the best way to mitigate systemd’s attack surface within whonix-16? Can this be done
using an app armour profile? How can I verify this?

related:

Self Support First Policy for Whonix applies.

You cannot “mitigate systemd’s attack surface”. You can try disabling some systemd-services, but risk breaking stuff. Not recommended.