Drag a concept onto its matching description — or click a concept then click the description.
Prevents processes from gaining more privileges than their parent
Ensures the container runs with a user ID that is not 0 (root)
Mounts the container's root filesystem as read-only
Drops all Linux capabilities, minimizing kernel privileges
Disables privileged mode, preventing access to host devices