Networking Concepts 23% Lesson 4 of 19

Lesson 1.2.3 — Traffic Management Appliances

Avatar Of Asad IjazAsad Ijaz ·Sep 12, 2026 ·8 min read
21% through domain
Illustration Of A Load Balancer, Proxy, And Cdn Alongside The Network+ N10-009 Lesson 1.2.3 Title Card

Domain 1.0 | Networking Concepts — 23% of exam

Learning Objectives

By the end of this lesson, you will be able to:

  • Describe the primary function of a load balancer and compare Layer 4 and Layer 7 load balancing
  • Explain common load-balancing algorithms and the purpose of health checks and session persistence
  • Distinguish a forward proxy from a reverse proxy based on which side of the connection each one serves
  • Describe how a content delivery network (CDN) reduces latency by caching content at geographically distributed edge servers
  • Compare load balancers, proxies, and CDNs side by side, and explain how they combine in a real traffic flow

Key Terms

TermDefinition
Load BalancerA device or service that distributes incoming traffic across multiple backend servers to improve capacity, reliability, and performance
Layer 4 Load BalancingLoad balancing performed using transport-layer information (IP address and port), without inspecting application content
Layer 7 Load BalancingLoad balancing performed using application-layer information (such as HTTP headers, URLs, or cookies), allowing more intelligent routing decisions
Health CheckA periodic test a load balancer performs against each backend server to confirm it’s available before sending it traffic
Session Persistence (Sticky Sessions)A load-balancing feature that ensures a given client’s requests are consistently sent to the same backend server for the duration of a session
Forward ProxyA proxy server that sits in front of clients, making requests to the internet on their behalf, often for filtering, caching, or anonymity
Reverse ProxyA proxy server that sits in front of one or more backend servers, handling requests on their behalf — commonly used for TLS termination, caching, and load distribution
CDN (Content Delivery Network)A geographically distributed network of edge servers that cache content closer to end users to reduce latency and offload the origin server
Edge ServerA server in a CDN located close to end users, which serves cached content directly rather than forwarding every request back to the origin
Origin ServerThe server that holds the authoritative, original copy of content that a CDN’s edge servers cache
Cache Hit / Cache MissA cache hit occurs when requested content is already stored at the edge server; a cache miss means the edge server must retrieve it from the origin
TLS/SSL OffloadingThe practice of terminating (decrypting) TLS/SSL traffic at a load balancer or reverse proxy rather than at each individual backend server, reducing backend CPU load

Explanation

A Different Kind of Infrastructure Device

Lessons 1.2.1 and 1.2.2 covered devices focused on basic connectivity and security. This lesson covers a third category: traffic management appliances — devices whose job is to make traffic distribution and delivery more efficient, rather than simply forwarding it (like a switch or router) or filtering it for threats (like a firewall or IDS/IPS). The three devices covered here — load balancers, proxies, and CDNs — are what let a popular website handle millions of simultaneous users, stay online when individual servers fail, and load quickly for users anywhere in the world.

Load Balancers: Spreading the Load

A load balancer distributes incoming client requests across a pool of backend servers rather than sending all traffic to a single server. This serves two purposes simultaneously: it increases capacity (multiple servers together can handle far more traffic than one), and it increases reliability (if one backend server fails, the load balancer simply stops sending it traffic and redirects to the remaining healthy servers).

Load balancers operate at one of two levels, and distinguishing between them is a core exam concept:

  • Layer 4 load balancing makes distribution decisions using only transport-layer information — source/destination IP address and port — without looking at the actual application content. It’s fast and protocol-agnostic, but it can’t make decisions based on what’s actually being requested.
  • Layer 7 load balancing makes decisions using application-layer information, such as the URL path, HTTP headers, or cookies. This allows much more intelligent routing — for example, sending all requests for /images/ to one server pool and requests for /api/ to a different pool — at the cost of requiring more processing power to inspect that content.

To decide which backend server receives a given request, a load balancer uses an algorithm. Common approaches include round robin (cycling evenly through the list of servers in order), least connections (sending new requests to whichever server currently has the fewest active connections), and weighted variants of either (giving more powerful servers a proportionally larger share of traffic). Regardless of algorithm, a load balancer continuously performs health checks — periodic tests against each backend server — so that a failed or unresponsive server is automatically removed from rotation until it passes health checks again.

One more concept worth knowing: session persistence (also called sticky sessions). Some applications store session-specific data (like a shopping cart) on whichever server first handled a user’s request. If a later request from that same user gets routed to a different backend server, that session data might not be there. Session persistence solves this by ensuring a given client is consistently routed to the same backend server for the life of their session, typically using a cookie or the client’s source IP address to make that determination.

Diagram Of A Load Balancer Distributing Traffic Across Servers Using Layer 4 Versus Layer 7 Decisions
How A Load Balancer Distributes Traffic Across A Server Pool

Proxies: Forward vs. Reverse

The word “proxy” simply means something acting on behalf of something else — and in networking, the critical question is always: on behalf of which side of the connection?

  • A forward proxy sits in front of clients and makes requests to the internet on their behalf. When a client is configured to use a forward proxy, its outbound requests go to the proxy first, and the proxy forwards them out to the destination server, often applying content filtering, caching, or logging along the way, and potentially hiding the client’s actual IP address from the destination. This is the model behind corporate web filtering — an organization routes all employee web traffic through a forward proxy that enforces browsing policy.
  • A reverse proxy sits in front of servers and handles requests on their behalf. From a client’s perspective, they appear to be talking directly to the destination server, but the reverse proxy is actually intercepting the request first, and may then forward it to one of several backend servers, terminate TLS encryption, cache responses, or apply security filtering — all before the request (or a cached response) reaches the client.

The directionality is the entire distinction: a forward proxy protects/represents the client side of a connection; a reverse proxy protects/represents the server side. In practice, the line between a reverse proxy and a load balancer has blurred considerably — many reverse proxy products include load-balancing features, and many load balancers include reverse-proxy-style capabilities like TLS offloading and caching. For the exam, focus on the conceptual distinction (which side each type serves) rather than assuming any one vendor’s product cleanly fits only one category.

Diagram Comparing Forward Proxy And Reverse Proxy Traffic Direction
Forward Proxy Versus Reverse Proxy — Which Side Each One Represents

CDNs: Bringing Content Closer to Users

A content delivery network (CDN) solves a different problem: even with a powerful, well-load-balanced set of origin servers, a user located far from those servers will experience latency simply due to the physical distance data has to travel. A CDN addresses this by distributing edge servers geographically close to end users, and caching content on those edge servers so that repeat requests can be served locally instead of traveling all the way back to the origin server.

When a user requests content served through a CDN, the request is routed to the nearest edge server. If that edge server already has a cached copy of the requested content, this is a cache hit, and the content is served immediately with minimal latency. If it doesn’t yet have a cached copy, this is a cache miss — the edge server retrieves the content from the origin server once, serves it to the user, and typically caches it for subsequent requests from other nearby users. This dramatically reduces both latency (content travels a much shorter physical distance) and load on the origin server (which no longer has to handle every single request directly).

CDNs are especially valuable for static content — images, videos, stylesheets, downloadable files — that doesn’t change per-user, though modern CDNs increasingly cache dynamic content as well using short cache lifetimes and smart invalidation. Beyond raw performance, CDNs commonly provide additional benefits like DDoS traffic absorption (since a distributed edge network can absorb and filter attack traffic before it ever reaches the origin) and improved availability during traffic spikes.

Diagram Of Cdn Edge Servers Caching Content Geographically Close To End Users
How A Cdn Caches Content Closer To Users Worldwide

Side-by-Side Comparison

DevicePrimary Problem SolvedKey MechanismTypical Placement
Load BalancerDistributing traffic across multiple servers for capacity and reliabilityAlgorithm-based distribution + health checksIn front of a pool of backend/origin servers
Reverse ProxyRepresenting servers to clients; centralizing TLS, caching, securityIntercepts and forwards requests on behalf of serversIn front of one or more backend servers
Forward ProxyRepresenting clients to the internet; filtering, anonymity, cachingIntercepts and forwards requests on behalf of clientsIn front of a group of internal clients
CDNReducing latency and origin load for geographically distributed usersCaching content at distributed edge serversGlobally distributed, between users and the origin
Diagram Comparing Load Balancer, Reverse Proxy, Forward Proxy, And Cdn Functions
Load Balancer, Reverse Proxy, Forward Proxy, And Cdn Compared

How These Devices Combine in a Real Deployment

These four technologies aren’t competing alternatives — they typically stack together in a single traffic path. Consider a popular website: a user’s request first reaches the CDN, which may serve it immediately from a cached edge copy (fastest possible path) or, on a cache miss, forward the request toward the origin infrastructure.

That request may pass through a reverse proxy, which terminates TLS and applies security policy, before reaching a load balancer, which distributes the request across a pool of application servers using Layer 7 rules and session persistence as needed. If any employees inside the organization need outbound internet access, their own traffic might separately pass through a forward proxy for content filtering — a completely different traffic flow serving a completely different purpose.

Understanding this layered flow helps make sense of scenario questions: a question describing slow load times for globally distributed users points toward a CDN gap; a question describing one server being overwhelmed while others sit idle points toward a load balancing problem; a question describing inconsistent user sessions points toward missing session persistence.

Recognition-Level Verification Concepts

This objective is descriptive/comparative, so there’s no hands-on configuration expected yet. It’s worth recognizing, conceptually, a few things you might observe when verifying these systems:

  • An HTTP response header such as X-Cache: HIT or X-Cache: MISS is a common (though vendor-specific) way a CDN or reverse proxy indicates whether a given response was served from cache.
  • A load balancer’s health check log typically shows each backend server’s status (healthy/unhealthy) and the timestamp of its last successful check.

You’ll work with actual configuration and troubleshooting for these systems in later domains as the course progresses into hands-on service configuration.

Common Exam Traps

  • Forward vs. reverse is about which side is represented, not which “direction” traffic physically flows. A forward proxy serves clients reaching out to the internet; a reverse proxy serves servers being reached by clients. If you remember nothing else, remember this pairing.
  • A CDN reduces latency through geographic caching; a load balancer increases capacity through traffic distribution. These solve genuinely different problems, even though both involve “spreading out” traffic in some sense — don’t conflate the two just because they sound similar.
  • Layer 4 vs. Layer 7 load balancing is about what information is used to make the decision — transport-layer addressing only (Layer 4) versus application-layer content like URLs and cookies (Layer 7) — not about which layer the traffic itself is “at.”
  • Session persistence exists because of statefulness in the application, not because of anything inherent to load balancing itself. A stateless application generally doesn’t need sticky sessions at all.
  • Modern products blur these categories — a single appliance or cloud service may simultaneously act as a reverse proxy, load balancer, and TLS terminator. Focus on the conceptual function being described in a question rather than assuming a one-to-one mapping between device categories and physical products.

Lesson 1.2.3 Practice Questions

Traffic Management Appliances · 17 questions · Network+ N10-009, Domain 1.0

1

What is the primary purpose of a load balancer?

B. A load balancer's primary purpose is distributing incoming traffic across multiple backend servers to improve capacity and reliability. Signature-based filtering (A) describes an IDS/IPS; geographic caching (C) describes a CDN; wireless-to-wired translation (D) describes an access point.
2
Scenario

An engineer needs a load-balancing solution that can route requests for /api/ to one server pool and requests for /images/ to a different server pool, based on the URL path. Which type of load balancing is required?

C — Layer 7 load balancing. Routing decisions based on the URL path require inspecting application-layer content, which is the defining characteristic of Layer 7 load balancing.
3

Which statement correctly distinguishes a forward proxy from a reverse proxy?

B. A forward proxy represents clients making outbound requests to the internet; a reverse proxy represents servers receiving inbound requests from clients.
4
Choose Two

Which two of the following are true about a content delivery network (CDN)?

A and C. A CDN caches content at edge servers close to end users (A), directly reducing latency for geographically distant users (C). B, D, and E are all false.
5
Exhibit

Based on this exchange, what does the X-Cache: HIT header indicate?

GET /logo.png HTTP/1.1 Host: cdn.example.com HTTP/1.1 200 OK X-Cache: HIT Content-Type: image/png
B. X-Cache: HIT indicates the requested content was already cached at the edge server and served directly, without needing to contact the origin server.
6
Scenario

A company notices that one of its three web servers is receiving significantly more traffic than the other two, even though all three have identical hardware. Which load-balancing algorithm would most directly address this imbalance?

B — Least connections. Sending new requests to whichever server currently has the fewest active connections directly addresses an existing load imbalance; round robin ignores current load entirely.
7

What is the primary purpose of a load balancer's health check?

B. A health check confirms a backend server is available and responsive before the load balancer sends it traffic, automatically removing an unhealthy server from rotation.
8
Choose Two

Which two of the following are true about session persistence (sticky sessions)?

A and C. Session persistence ensures consistent routing to the same backend server (A), typically via a cookie or source IP (C). B, D, and E are all false.
9
Scenario

Users around the world report that a company's website loads noticeably faster in North America, where the origin servers are located, than in Asia and Europe. Which technology would most directly address this specific problem?

B — A content delivery network (CDN) with edge servers distributed globally. This is a textbook latency-due-to-distance problem, directly addressed by serving cached content from edge locations near users in Asia and Europe.
10

Which of the following best describes TLS/SSL offloading?

B. TLS/SSL offloading means terminating (decrypting) TLS/SSL connections at a centralized load balancer or reverse proxy rather than requiring every backend server to do it individually.
11
Exhibit

Based on this health check log, what will the load balancer most likely do?

LB-HEALTH 2026-09-14 09:15:02 Server=web-02 Status=UNHEALTHY LastCheck=Failed (timeout) LB-HEALTH 2026-09-14 09:15:02 Server=web-01 Status=HEALTHY LastCheck=OK LB-HEALTH 2026-09-14 09:15:02 Server=web-03 Status=HEALTHY LastCheck=OK
B. With web-02 marked UNHEALTHY, the load balancer removes it from rotation and stops sending it traffic until it passes health checks again, continuing to serve traffic through web-01 and web-03.
12

A company wants to enforce content-filtering policy on all outbound web browsing from its internal employees. Which device is most appropriate for this purpose?

B — A forward proxy. Enforcing content-filtering policy on outbound client traffic is the classic forward proxy use case.
13
Scenario

An online retailer's shopping cart feature breaks intermittently — items added to a cart sometimes disappear when the user proceeds to checkout. An engineer suspects the load balancer is routing the user's requests to different backend servers that don't share session data. Which feature would most likely resolve this?

B. Enabling session persistence ensures a given user's requests are consistently routed to the same backend server for their session, resolving this shopping-cart-data-inconsistency symptom.
14
Choose Two

Which two of the following are typical benefits a CDN provides beyond raw latency reduction?

A and B. CDNs commonly absorb DDoS traffic before it reaches the origin (A) and improve availability during traffic spikes (B). C, D, and E are all false.
15

Which statement best describes the relationship between reverse proxies and load balancers in modern products?

B. Modern reverse proxy and load balancer products frequently overlap — many reverse proxies include load-balancing features, and many load balancers include reverse-proxy-style features like TLS termination.
16
Scenario

A network engineer wants to reduce the amount of processing performed by backend web servers by handling encryption and decryption of client connections at a single centralized point instead. Which technique addresses this goal?

B. Centralizing encryption/decryption at a load balancer or reverse proxy rather than requiring each backend server to handle it individually is the definition of TLS/SSL offloading.
17
Exhibit

Based on this traffic flow diagram, which device is responsible for distributing the request across multiple application servers?

Client Request -> CDN Edge Server (cache miss) -> Reverse Proxy (TLS termination) -> Load Balancer -> App Server Pool
C — The load balancer. In this flow, the load balancer is explicitly responsible for distributing the request across the pool of application servers, after the CDN has handled caching and the reverse proxy has handled TLS termination.
📝

Summary

Load balancers distribute traffic across a pool of backend servers using Layer 4 or Layer 7 decision-making, algorithms like round robin or least connections, continuous health checks, and optional session persistence for stateful applications

Forward proxies represent clients making outbound requests; reverse proxies represent servers receiving inbound requests — the direction of representation is the entire distinction

CDNs reduce latency and origin server load by caching content at geographically distributed edge servers, serving cache hits locally and only falling back to the origin on a cache miss

These technologies commonly stack together in a single real-world traffic path: CDN, then reverse proxy, then load balancer, then the actual application servers

Modern products increasingly blur the lines between reverse proxies and load balancers — focus on the underlying function being described rather than assuming a strict one-to-one mapping to specific products

Avatar Of Asad Ijaz

Lead Networking Architect and Editor at NetworkUstad. BS in Computer Networks and Security, CCNP and CCNA certified, with 11+ years of experience in enterprise network design, implementation, and troubleshooting. Writes practical tutorials on routing, IPv4 management, network automation, and security fundamentals.