Courseiva
easyMultiple Select

200-901 Practice Question: Which TWO HTTP methods are considered safe…

Which TWO HTTP methods are considered safe according to HTTP/1.1 specification?

⚠ Common exam trap

Cisco often tests the misconception that idempotent methods (like PUT and DELETE) are also safe, but idempotence only guarantees repeated requests have the same effect, not that they are read-only.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

GET

According to the HTTP/1.1 specification (RFC 7231), a method is 'safe' if it is defined as not having side effects on the server — essentially, it is intended only for information retrieval. Option B, GET, is safe because it is designed solely to retrieve a representation of a resource without altering server state. Option D, HEAD, is also safe because it is identical to GET except that the server must not return a message body, making it a read-only metadata request. The unmarked options do not belong: PUT (A) and DELETE (C) are unsafe because they create/replace and remove resources respectively, and POST (E) is unsafe because it submits data that often changes server state or triggers processing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    PUT

    Why it's wrong here

    PUT is idempotent but not safe: it modifies the resource at the target URI, so it changes server state. It is tempting because idempotent methods are often grouped with safe ones, yet safety concerns read-only behaviour. GET and HEAD are the safe methods under HTTP/1.1.

  • ✓

    GET

    Why this is correct

    GET is defined as safe because it is a read-only retrieval method: it must not alter server state, making it free of side effects. This contrasts with unsafe methods such as POST and DELETE, which are expected to change resource state.

  • ✗

    DELETE

    Why it's wrong here

    DELETE is not safe: HTTP/1.1 defines safe methods as those that do not alter server state, and DELETE removes the target resource. It is tempting because DELETE is idempotent, so repeating it yields the same result, and would be correct if the question asked about idempotent methods rather than safe ones.

  • ✓

    HEAD

    Why this is correct

    HEAD is safe because it returns only the response headers for a resource, identical to GET but without a body, so no server state changes. Like GET, it is purely a retrieval operation, distinguishing it from state-changing methods such as PUT or POST.

  • ✗

    POST

    Why it's wrong here

    POST is unsafe because it submits data for processing, changing server state, and is neither safe nor idempotent. It is tempting because POST is the standard method for form submission and resource creation, and would be the right choice when the requirement is to send data that modifies a resource rather than merely retrieve it.

About these practice questions

This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.