200-901 Understanding and Using APIs Practice Question
Which TWO of the following HTTP methods are considered safe (idempotent and not modifying server state)? (Select two.)
⚠ Common exam trap
The trap is conflating 'idempotent' with 'safe' — candidates pick PUT or DELETE because they are idempotent, forgetting that safety additionally requires no server-state modification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
GET
GET (D) is safe because it is defined by RFC 7231 as a read-only method that retrieves a representation without altering server state, and repeating it yields the same result (idempotent). HEAD (E) is also safe because it returns only the response headers for the same resource a GET would target, performing no state change and being idempotent. PUT (A) is not safe because it creates or replaces the target resource, modifying server state, even though it is idempotent. DELETE (B) is not safe because it removes the target resource, changing server state (it is idempotent but not safe). POST (C) is neither safe nor idempotent, since it submits data that typically creates or processes a resource and can produce different results on each call.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
PUT
Why it's wrong here
PUT creates or replaces the target resource with the request payload, altering server state, so it fails the safe criterion despite being idempotent. It is tempting because repeating an identical PUT yields the same representation, but idempotence alone does not satisfy safety — GET and HEAD do not modify state.
- ✗
DELETE
Why it's wrong here
DELETE removes the target resource, changing server state, so it cannot be safe; it is idempotent in effect but still modifies state. It is tempting because repeated identical DELETE requests leave the same end state, yet the question requires methods that do not modify server state at all.
- ✗
POST
Why it's wrong here
POST submits data that creates or modifies server state, so it is neither safe nor idempotent; repeating it can duplicate resources. It is tempting because POST is the standard method for sending data, but that is precisely why it fails here — safe methods such as GET and HEAD only retrieve representations without altering state.
- ✓
GET
Why this is correct
GET is defined as a safe method because it retrieves a representation without altering server state, and it is idempotent since repeated identical requests produce the same effect. This directly satisfies the stem's requirement for methods that are both idempotent and non-modifying.
- ✓
HEAD
Why this is correct
HEAD is safe and idempotent: it returns only response headers identical to those GET would return, with no message body, and never modifies server state. This satisfies the stem's requirement for methods that are idempotent and do not alter resources.
Go deeper
Related to this question
About these practice questions
This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.