...can improve the nodes security (like, /var, /boot, /tmp, /home and /usr)
5. bridge is ok
9. it could be unnumbered advice about how you can hardening any setup, but any security improvement have a downside (time to spent, watch your systems, lower your performance, and many many more)
10...