mediumMultiple Choice
200-901 Practice Question: A REST API returns a 500 Internal Server Error…
A REST API returns a 500 Internal Server Error when a client sends a malformed JSON payload. What is the most appropriate HTTP response code to indicate a client-side error?
⚠ Common exam trap
Cisco often tests the distinction between 400 (syntax errors) and 422 (semantic errors), leading candidates to mistakenly choose 422 when the question explicitly states 'malformed JSON payload' (a syntax issue), not a validation failure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
400 Bad Request
A 400 Bad Request is the correct response because the client sent a malformed JSON payload, which is a client-side error. HTTP 400 indicates that the server cannot process the request due to something perceived as a client error (e.g., malformed syntax). This aligns with RFC 7231, which defines 400 as appropriate for requests with invalid syntax or structure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
400 Bad Request
Why this is correct
400 Bad Request signals that the server cannot process the request because the client sent malformed syntax, such as invalid JSON. It correctly attributes the fault to the client, whereas 500 indicates a server-side failure.
- ✗
401 Unauthorized
Why it's wrong here
401 is used when authentication is required and has failed or not been provided.
- ✗
403 Forbidden
Why it's wrong here
403 Forbidden signals that the server understood the request but refuses to authorise it, so it cannot convey malformed JSON. It is tempting because both are 4xx client errors, but 403 addresses authenticated users lacking permission on a resource — the correct choice here is 400 Bad Request, which reports the syntax fault itself.
- ✗
422 Unprocessable Entity
Why it's wrong here
422 Unprocessable Entity is the standard code for a syntactically valid request whose content fails semantic validation, not for malformed JSON. It would be correct if the JSON parsed but contained invalid field values or violated schema rules.
Go deeper
Related to this question
About these practice questions
One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.