Load balancer
A device or service that spreads incoming requests across a pool of servers and removes failed ones from rotation, improving availability and capacity for the service behind it.
A load balancer receives client requests addressed to one service and distributes them across a pool of back-end servers. It chooses a server by a scheduling method, such as simple rotation or sending each request to the least busy server, and runs health checks so that a failed server stops receiving traffic. Layer 4 load balancers decide from addresses and ports; layer 7 load balancers read the application request itself, such as an HTTP path, and can route on its content.
Its main security contribution is availability. Spreading load and routing around failures helps keep a service running when individual servers fail, and the back-end servers need not be reachable directly. It is not a full defence against denial of service, since a large enough flood can overwhelm the load balancer itself, and it is a single point of failure unless deployed redundantly. Where it terminates TLS, traffic is decrypted on the load balancer, which then holds private keys that need protecting and becomes a point where inspection, for example by a web application firewall, can happen.
Exam relevance: a scenario may turn on whether a candidate notices the load balancer itself as a single point of failure, or as the place where encrypted traffic is decrypted.