Also those two choices are more mutually exclusive than complementing each other.
--force-renewal
will force an actual renewal (even if the cert doesn't need to be renewed) while
--dry-run
tries to simulate/validate the renewal process (but doesn't actually "do/change" anything)