A security review of a containerized application finds that the running process has far more privileges than it needs. Which TWO changes reduce the attack surface of the container at runtime? (Choose two.)
By default many images run as root, so a compromised process would hold root privileges inside the container namespace and could exploit any kernel or mount weakness. Specifying a non-root user in the image or at run time removes that privilege. It directly reduces what an attacker can do after a successful compromise, which is exactly the goal of the review.
Why this answer
Least privilege for containers is enforced along two axes: the identity the process runs under and the kernel capabilities it retains. Running as a non-root user removes root-owned access inside the container, while dropping unneeded capabilities prevents privileged kernel operations even if the process is compromised. Options that grant daemon access, full privileges, or broader network exposure all move in the opposite direction.
Exam trap
The trap here is confusing isolation features with privilege reduction, so flags like --privileged or a mounted Docker socket feel like convenience features when they actually expand the attack surface.