Courseiva
easyMultiple Select

200-901 Practice Question: Which TWO of the following are true about REST…

Which TWO of the following are true about REST API design principles?

⚠ Common exam trap

Cisco often tests the distinction between idempotency and safety, and the trap here is confusing PATCH with PUT or assuming POST must be idempotent like PUT.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

GET requests should not change state

Option B is correct because REST treats GET as a safe method, meaning it must be read-only and must not alter server state, so clients and intermediaries can cache or retry it without side effects. Option E is correct because PUT is defined by HTTP as idempotent and can target a client-known URI, so it may create the resource if it does not exist or fully replace it if it does, making it valid for both creation and update. Option A is wrong because PATCH performs a partial modification, whereas PUT is the method used for full replacement. Option C is wrong because POST is neither safe nor idempotent, so repeating it can create duplicate resources or trigger repeated side effects. Option D is wrong because DELETE responses are not required to include a body; a 204 No Content with an empty body is a standard and valid response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    PATCH is used for full replacement of a resource

    Why it's wrong here

    PATCH applies partial modifications; full replacement is PUT's role. PATCH is tempting because both target an existing resource and both can carry a body, so the verbs look interchangeable, yet only PUT semantics require the complete representation to overwrite the resource.

  • ✓

    GET requests should not change state

    Why this is correct

    GET is defined as a safe method, meaning it must not alter server state; it only retrieves representations. This satisfies the stem's REST design principle, distinguishing safe retrieval from unsafe operations such as POST, PUT and DELETE that modify resources.

  • ✗

    POST requests should be idempotent

    Why it's wrong here

    POST is neither safe nor idempotent; repeating it can create duplicate resources, which is why PUT and DELETE carry idempotency. It is tempting because POST does submit data to a server, but that submission creates or processes rather than reproducibly replacing a known resource.

  • ✗

    DELETE responses must always contain a body

    Why it's wrong here

    DELETE may return 204 with an empty body, so a body is never mandatory. It is tempting because some APIs do return a representation or status payload after deletion, but the HTTP specification permits no content, and 204 is the common response.

  • ✓

    PUT can be used for both creation and update of resources

    Why this is correct

    PUT is idempotent and can create or replace a resource at a given URI.

About these practice questions

One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.