What is the best way to mitigate systemd’s attack surface within whonix-16? Can this be done
using an app armour profile? How can I verify this?
related:
Self Support First Policy for Whonix applies.
You cannot “mitigate systemd’s attack surface”. You can try disabling some systemd-services, but risk breaking stuff. Not recommended.