easyMultiple Select
200-901 Practice Question: Which TWO HTTP methods are considered safe…
Which TWO HTTP methods are considered safe according to HTTP/1.1 specification?
⚠ Common exam trap
Cisco often tests the misconception that idempotent methods (like PUT and DELETE) are also safe, but idempotence only guarantees repeated requests have the same effect, not that they are read-only.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
GET
According to the HTTP/1.1 specification (RFC 7231), a method is 'safe' if it is defined as not having side effects on the server — essentially, it is intended only for information retrieval. Option B, GET, is safe because it is designed solely to retrieve a representation of a resource without altering server state. Option D, HEAD, is also safe because it is identical to GET except that the server must not return a message body, making it a read-only metadata request. The unmarked options do not belong: PUT (A) and DELETE (C) are unsafe because they create/replace and remove resources respectively, and POST (E) is unsafe because it submits data that often changes server state or triggers processing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
PUT
Why it's wrong here
PUT is idempotent but not safe: it modifies the resource at the target URI, so it changes server state. It is tempting because idempotent methods are often grouped with safe ones, yet safety concerns read-only behaviour. GET and HEAD are the safe methods under HTTP/1.1.
- ✓
GET
Why this is correct
GET is defined as safe because it is a read-only retrieval method: it must not alter server state, making it free of side effects. This contrasts with unsafe methods such as POST and DELETE, which are expected to change resource state.
- ✗
DELETE
Why it's wrong here
DELETE is not safe: HTTP/1.1 defines safe methods as those that do not alter server state, and DELETE removes the target resource. It is tempting because DELETE is idempotent, so repeating it yields the same result, and would be correct if the question asked about idempotent methods rather than safe ones.
- ✓
HEAD
Why this is correct
HEAD is safe because it returns only the response headers for a resource, identical to GET but without a body, so no server state changes. Like GET, it is purely a retrieval operation, distinguishing it from state-changing methods such as PUT or POST.
- ✗
POST
Why it's wrong here
POST is unsafe because it submits data for processing, changing server state, and is neither safe nor idempotent. It is tempting because POST is the standard method for form submission and resource creation, and would be the right choice when the requirement is to send data that modifies a resource rather than merely retrieve it.
Go deeper
Related to this question
About these practice questions
This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.