SOA-C02 Networking and Content Delivery Practice Question
A SysOps Administrator is configuring a Network Load Balancer (NLB) for a TCP-based application. The application requires that clients see the original source IP address of the request. Which configuration should the Administrator use?
⚠ Common exam trap
It's easy for candidates to confuse NLB and ALB behavior, assuming that preserving source IP requires a special configuration like Proxy Protocol, when in fact NLBs do this by default for TCP traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the NLB default behavior; no additional configuration needed.
Network Load Balancers (NLBs) preserve the original source IP address of clients by default when forwarding TCP traffic to targets. This is because NLBs operate at Layer 4 and do not terminate the TCP connection; instead, they pass packets directly to the backend, allowing the target to see the client's IP. No additional configuration is required for this behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use the NLB default behavior; no additional configuration needed.
Why this is correct
A Network Load Balancer operates at Layer 4 and forwards packets as-is to the registered targets, so the client IP address is preserved in the original packet headers by default. Unlike Layer 7 load balancers, the NLB does not terminate the TCP connection or perform NAT on the source address. Therefore, no additional settings, headers, or protocols are required to make the client source IP visible to the backend.
- ✗
Use an Application Load Balancer instead, which preserves the source IP.
Why it's wrong here
An Application Load Balancer operates at Layer 7 and terminates the client connection, then opens a new TCP connection to the target. Consequently, the target sees the source IP of the ALB node, not the original client. The ALB instead inserts X-Forwarded-For (and related) HTTP headers so the application can log the client IP, but this is not true preservation of the network-layer source address. Using an ALB would actually lose the packet-level source IP that the NLB preserves natively.
- ✗
Enable cross-zone load balancing on the NLB.
Why it's wrong here
Cross-zone load balancing on an NLB controls traffic distribution across targets in multiple Availability Zones, allowing each load balancer node to send traffic to targets outside its own zone. It does not alter the packet forwarding behavior or manipulate IP headers in any way. Enabling cross-zone load balancing neither enables nor disables source IP preservation; the NLB continues to pass the original source IP in all cases, so this setting is irrelevant to the requirement.
- ✗
Enable Proxy Protocol v2 on the target group.
Why it's wrong here
Proxy Protocol v2 is an optional header the NLB can prepend to the TCP stream to convey connection metadata such as the original source and destination IP addresses and ports. However, this is used when you need additional metadata behind an intermediate proxy or when you want the target to parse a structured header—it is not required to preserve the source IP because the NLB already exposes the client IP at the packet layer. Moreover, enabling Proxy Protocol without corresponding support on the target could cause connectivity issues, making it an unnecessary and potentially harmful configuration for this scenario.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.