mediumMultiple Select
200-901 Practice Question: When designing a REST API for managing network…
When designing a REST API for managing network devices, which two principles should be followed to ensure statelessness?
⚠ Common exam trap
Cisco often tests the distinction between statelessness and other REST principles like idempotency or versioning; the trap here is that candidates confuse 'statelessness' with 'idempotency' or 'backward compatibility', leading them to select options that are valid REST practices but do not address the statelessness constraint.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
All state information is stored on the client.
Statelessness in REST means the server does not retain any client context between requests, so option A is correct: all state information is stored on the client, which sends whatever context is needed with each call. Option D is also correct because each request from client to server must contain all information needed to understand and complete the request, allowing any server instance to handle it independently. Option B is wrong because maintaining session data and identifying clients via cookies is the opposite of statelessness, creating server-side session state. Option C is unrelated to statelessness; version numbers in endpoints address backward compatibility, not state management. Option E is incorrect because POST is generally non-idempotent, and idempotency of responses is not a statelessness principle.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
All state information is stored on the client.
Why this is correct
Statelessness requires the client to hold session state, sending credentials and context with every call. Storing state on the client means the server keeps no session between requests, so each call is independently interpretable and horizontally scalable.
- ✗
The server maintains session data and identifies clients via cookies.
Why it's wrong here
Storing session state server-side and tracking clients via cookies directly contradicts statelessness, which requires each request to carry all context needed. Cookies are tempting because they underpin traditional session-based web authentication, the right approach when a stateful login session across many pages is genuinely required.
- ✗
API endpoints include version numbers to support backward compatibility.
Why it's wrong here
Version numbers in URIs address backward compatibility and change management, not statelessness; each request must instead carry all state needed for the server to process it. It is tempting because versioning is a REST design convention, and would be correct when evolving an API without breaking existing clients.
- ✓
Each request from client to server must contain all information needed to understand and complete the request.
Why this is correct
Statelessness demands that every request carries all data required for the server to process it, including authentication and parameters. The server then holds no session context, so any node can handle any request without prior interaction.
- ✗
Responses are idempotent for all POST requests.
Why it's wrong here
POST is neither safe nor idempotent by HTTP definition; repeated identical POSTs create duplicate resources, so mandating idempotent responses misstates the constraint. Idempotency is tempting because it genuinely applies to PUT and DELETE, where repeating the same request yields the same server state.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.