CompTIA Network+ (N10-008): Compare and Contrast Network Devices and Where They Belong

When I coach Network+ candidates on device questions, I tell them the exam is rarely asking only, “What is this device?” More often, it is asking, “What role does this device play, and where should it sit in the traffic path?” Honestly, that’s the part you really need to get comfortable with. For clarity, this article is written for the retired CompTIA Network+ N10-008 objective language, but the core device concepts still carry directly into N10-009.

The fastest way to miss these questions is to fixate on device names instead of stopping to ask what the device is actually doing on the network. CompTIA usually wants the best-fit answer, not just the one that could work in theory. Sure, a router, firewall, and Layer 3 switch can all move traffic between networks in some fashion, but they don’t belong in the same place and they’re definitely not solving the same problem. In most real networks, where a device belongs comes down to trust boundaries, traffic flow, segmentation, manageability, and how gracefully the design keeps working when something fails.

The Basics That Make These Device Questions Way Easier

I usually tell people to use the OSI model as a sort of elimination checklist. If the scenario is talking about bits, signals, or media, you’re probably down at Layer 1. If the question starts talking about MAC addresses, VLANs, or switching behavior, you’re probably in Layer 2 territory. If the scenario is about IP routing or default gateways, that’s your cue to think Layer 3. If the device is doing application awareness, proxy functions, URL filtering, or reverse proxy work, you’re moving into higher-layer inspection territory. Be careful with mixed-function devices: a wireless router, NGFW, or multilayer switch may operate across several layers, so the exam usually wants the primary role in that scenario.

And keep the classic domain rules straight: hubs leave everyone in one shared collision domain, switches separate collision domains per port, and routers or other Layer 3 boundaries break up broadcast domains. On switched networks, each VLAN is its own broadcast domain. That small detail ends up solving a lot of questions, honestly.

And, finally, pay really close attention to the verbs in the question. Forward means send onward, filter means allow or deny by rule, route means choose a next hop between networks, inspect means evaluate packet or session details, aggregate means combine links or tunnels, and terminate means end a service or tunnel locally. A lot of the time, CompTIA is hiding the answer right inside that action word.

Quick Reference: Device, Function, Placement, and Common Mix-Ups

DeviceMain FunctionBest PlacementCommon Confusion
HubRepeats bits to all portsLegacy onlySwitch
BridgeLayer 2 filtering between segmentsLegacy concept; modern switch equivalentSwitch
Layer 2 switchMAC-based forwarding, VLANsAccess layer/IDFHub, Layer 3 switch
Layer 3 switchInter-VLAN routing with SVIs, high-throughput LAN routingDistribution layer or routed accessRouter
RouterRouting between networks, WAN/edge functionsWAN edge, branch edge, internet edgeLayer 3 switch, firewall
APBridges wireless clients to wired LANUser coverage areasWireless router
WLC / cloud WLAN managementCentral AP policy and controlOn-prem controller, virtual controller, or cloud management planeAP itself
FirewallTrust-boundary policy enforcementPerimeter, DMZ, internal segmentationRouter
IDS / IPSDetects or blocks malicious trafficIDS out-of-band; IPS inlineFirewall
Proxy / reverse proxyApplication mediationClient egress or in front of appsFirewall, load balancer
VPN concentratorTerminates many VPN tunnelsPerimeter/remote access edgeFirewall, router
NACAdmission control and segmentation enforcementCentral policy with access-layer enforcementFirewall
Load balancerDistributes traffic across serversIn front of server poolsReverse proxy
Modem / ONTProvider media handoffAt or near demarc/provider handoffRouter
Media converter / SFPPhysical media adaptationWhere copper/fiber mismatch existsSwitching or routing device

Core Infrastructure: What Belongs Where and Why

Hub: legacy Layer 1 repeater. It just blasts incoming bits out every other port, which means all the connected devices are sharing the same medium and collision domain. In a modern network, that’s almost never the right production answer.

Bridge: an older Layer 2 filtering device. A useful exam fact is that a modern switch is basically a multiport bridge.

Layer 2 switch: the normal access-layer device. It learns source MAC addresses in a CAM table, sends known unicast traffic only where it needs to go, floods broadcasts inside the VLAN, and floods unknown unicast traffic until it learns where the destination sits. Managed switches give you VLANs, trunks, port security, PoE, QoS, and STP/RSTP support, which is why they’re so common in business networks. Unmanaged switches can be fine in tiny flat networks, but they’re a poor fit anywhere segmentation or troubleshooting really matters.

Layer 3 switch: commonly used for inter-VLAN routing inside a campus. The key implementation concept is the SVI, or Switch Virtual Interface, which gives a VLAN a Layer 3 gateway IP. In a lot of enterprise LANs, the host default gateway is actually an SVI on a multilayer switch, not a separate router. Layer 3 switches are usually built for fast LAN routing, especially when you’re moving traffic between VLANs.

Router: best fit at the WAN edge, branch edge, or internet edge. Routers are often chosen for WAN connectivity, NAT/PAT, VPN functions, and path control features, depending on the platform. Important exam correction: the default gateway is simply the Layer 3 next hop for off-subnet traffic. That next hop could be a router interface, a firewall interface, or an SVI on a Layer 3 switch.

Classic compare points: if the clue is MAC learning, VLANs, trunks, or port security, think switch. If the question is about inter-VLAN routing in a campus, start with Layer 3 switch. If it sounds like WAN handoff, branch connectivity, or edge routing, think router.

Switching Mechanics That Drive Placement

Access switches belong at the edge because that’s where endpoint density, PoE, VLAN assignment, and admission control matter most. Access ports carry one VLAN for endpoints. Trunk ports carry multiple VLANs between switches or to devices like APs, firewalls, or routers using 802.1Q tagging. The native VLAN matters because untagged frames on a trunk are associated with that VLAN.

Redundant Layer 2 links require STP or RSTP to prevent loops. Without loop prevention, you can end up with broadcast storms, MAC table instability, and some pretty ugly outages. That’s why unmanaged switches in the wrong spot can cause problems really quickly. A common troubleshooting clue is users reporting intermittent connectivity while the switch MAC table keeps bouncing between ports.

Inter-VLAN Routing and Default Gateway Design

There are three classic ways to route between VLANs: router-on-a-stick, multilayer switching with SVIs, and less commonly a firewall interface design. Router-on-a-stick uses a single router interface with VLAN subinterfaces over a trunk link. It does work, but it’s usually better for smaller environments. Multilayer switching uses an SVI for each VLAN, and that’s the classic campus answer. Routed access exists in modern designs too, so don’t assume distribution-layer routing is the only valid option; it’s just the most common simplification for Network+.

Text topology: Users → access switch → trunk uplink → Layer 3 switch with SVIs → core/edge. If the question says hosts in VLAN 10 can’t reach VLAN 20, I’d check for missing SVIs, routing being disabled, wrong gateway addresses, or a broken trunk first.

Wireless Design and Placement Fundamentals

An AP bridges wireless clients onto the wired LAN. In enterprise networks, APs usually map SSIDs to VLANs, and that often rides over a trunk uplink. Placement is really about coverage, capacity, and roaming, not just whether the signal shows up on a phone. 2.4 GHz reaches farther but overlaps more and has fewer clean channels, while 5 GHz usually gives you better capacity and more channel options. and 6 GHz adds even more clean spectrum where it’s supported. Poor AP placement, sloppy channel planning, and co-channel interference are exactly how you end up with that classic “Wi-Fi is flaky” complaint.

A traditional WLC centralizes AP policy and control. Some deployments use on-prem appliances or virtual controllers, while others use cloud-managed WLAN platforms, which aren’t exactly the same thing as a classic hardware WLC. For exam purposes, distinguish the control plane from the data plane: management may be centralized while client traffic may still break out locally.

A wireless router is a SOHO all-in-one device combining AP, switch, router, NAT, and firewall functions. That’s perfectly fine for a home office, but it’s usually not the best-fit answer for enterprise wireless growth.

Firewall, IDS/IPS, Proxy, and VPN: How to Think About Them

A firewall belongs at a trust boundary: perimeter, DMZ edge, or internal segmentation point. Stateless ACL filtering just checks packets against rules without tracking the session behind them. Stateful inspection tracks connections in a state table, which is why return traffic handling is smarter and easier to manage. NGFW features may also add application awareness, URL filtering, and IPS-style inspection. Also remember: NAT is not a security control. Both routers and firewalls can perform NAT/PAT.

IDS vs IPS: an IDS typically detects and alerts out-of-band, often using a SPAN/mirror port or TAP; host-based IDS also exists. An IPS sits inline, so it can actually block traffic. Inline placement also raises questions about latency and whether the device should fail open or fail closed. If the question says monitor, alert, or passive visibility, think IDS. If the question says block, prevent, or inline, think IPS.

Proxy: a forward proxy represents the client for outbound web access and may provide authentication, caching, and URL filtering. A reverse proxy stands in for the server, often in a DMZ, and may terminate TLS, add security headers, hide backend servers, or work with a WAF. A lot of modern Layer 7 load balancers also behave like reverse proxies, so you’ve really got to read the requirement carefully.

VPN concentrator: terminates many encrypted tunnels for remote access or site-to-site connectivity. You’d usually place it at the perimeter, often alongside firewall integration. With split tunneling, only corporate traffic goes through the VPN. With full tunneling, all traffic does. If the VPN connects but users still can’t reach internal resources, I’d check the tunnel routes, ACLs, NAT exemptions, and user permissions.

NAC: think centralized policy with access-layer enforcement. NAC often ties together 802.1X, RADIUS, switches, APs, and directory services. The enforcement point is wherever the device connects, even if the policy engine itself lives somewhere else. Typical outcomes are normal access, guest access, a quarantine VLAN, or a remediation network.

Availability, Performance, and the WAN Edge

A load balancer sits in front of a server pool and uses a VIP to distribute sessions to healthy backends. It can work at Layer 4 or Layer 7, do health checks and session persistence, offload TLS, and in a lot of products it overlaps with reverse proxy features. If it isn’t redundant, though, it turns into a single point of failure all by itself.

QoS matters where congestion happens. Usually, the trust boundary for marking is close to the access layer for phones, while queuing matters more at uplinks and WAN edges. Think DSCP, CoS, classification, marking, and queuing. Voice traffic often sounds fine until the links get busy, and then QoS suddenly becomes really important.

Link aggregation improves aggregate bandwidth and resilience, but one flow is typically still limited to one member link based on hashing behavior. Know the real concept, not the common myth you hear tossed around. Redundancy also includes dual uplinks, first-hop redundancy, HA firewalls, and controller failover.

At the provider edge, the demarcation point is the boundary between provider and customer responsibility. A modem or ONT is often at or near that handoff. ONTs are common with fiber, cable modems with DOCSIS, and DSL modems with DSL services. CSU/DSU is legacy leased-line terminology that may still appear conceptually. CPE means customer premises equipment. SD-WAN belongs at the branch edge and adds centralized orchestration, overlay tunnels, transport independence, and application-aware path selection across MPLS, broadband, LTE, or 5G.

Placement by Zone

Access layer: endpoint switches, APs, PoE phones, cameras, printers, IoT, and NAC enforcement. Distribution: aggregation, policy, and often inter-VLAN routing. Core: fast backbone transit with minimal unnecessary policy in the classic campus model. Perimeter: edge router, firewall, VPN, IDS/IPS, ISP handoff. DMZ: public-facing services, reverse proxies, load balancers, and segmentation controls. Branch/SOHO: often integrated devices, but with less modularity and scale.

Compact Exam Scenarios to Practice With

Users on one floor need wired access, PoE phones, and separate voice/data VLANs: managed access switch with PoE and QoS. Definitely not a hub, and not an unmanaged switch either.

Two VLANs in a building cannot communicate: multilayer switch or router performing inter-VLAN routing. I’d check the SVIs, trunks, and default gateways first.

Remote workers need encrypted access to internal apps: VPN concentrator or firewall VPN at the edge, not an IDS.

Public web app needs isolation and backend protection: firewall plus DMZ, usually with reverse proxy and possibly load balancer. And no, the database really shouldn’t be sitting in the DMZ.

Guest Wi-Fi must reach the internet but not internal servers: APs with guest SSID mapped to isolated VLAN, enforced by firewall policy or NAC controls.

Troubleshooting When Placement Is Wrong

Wi-Fi clients connect but get no network access: check SSID-to-VLAN mapping, AP trunking, DHCP scope reachability, controller policy, and PoE status. Wrong VLAN tagging is a classic culprit here.

Local LAN works but internet is down: inspect the edge path in order: default gateway, firewall/router, NAT/PAT, default route, and modem/ONT handoff at or near demarc. That’s where best-fit placement thinking really starts to pay off.

Intermittent LAN slowdown and strange outages: suspect a Layer 2 loop, STP issue, duplex mismatch, or overloaded uplink. I’d check switch logs, interface errors, MAC flapping, and spanning-tree status.

Common Exam Traps and How to Pick the Best Answer

Watch for these traps: default gateway does not always mean router; NAT does not automatically mean firewall; a WLC manages APs but is not the radio access device; IDS detects, IPS prevents; VLANs define broadcast domains; and a switch is effectively a multiport bridge.

When two answers could technically work, go with the one that best matches the wording of the requirement. Need to detect? IDS. Need to prevent inline? IPS. Need to route between VLANs in a campus? Layer 3 switch. Need to enforce a trust boundary? Firewall. Need to terminate provider media? Modem or ONT. Need to front multiple servers? Load balancer or reverse proxy depending on whether the clue emphasizes distribution or application mediation.

Final Rapid Review

Access switch connects endpoints. AP provides wireless access. Layer 3 switch commonly provides campus default gateways using SVIs. Router belongs at WAN and edge interconnection points. Firewall enforces policy at trust boundaries. IDS watches; IPS blocks. Proxy mediates application traffic. A VPN concentrator is there to terminate tunnels. A load balancer distributes traffic across servers. A modem or ONT terminates the provider media at or near the demarc. Media converters and SFPs solve physical connectivity problems, not routing or security problems.

That’s the mindset Network+ rewards: figure out the function, figure out the zone, and then pick the device that fits there with the least complexity and the best overall design.