mediumMultiple Select
350-401 Practice Question: Which two statements about REST API HTTP methods…
Which two statements about REST API HTTP methods are true? (Choose two.)
⚠ Common exam trap
350-401 often tests the safe-versus-idempotent distinction, tricking candidates into assuming POST is idempotent or that DELETE is not — the key is that idempotency concerns server state, not response codes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
GET is a safe method that must not change server state.
Option A is correct because GET is defined by the HTTP specification as a safe method, meaning it is intended only for retrieval and must not alter server state. Option D is correct because PUT is idempotent—repeating the same request yields the same result—and it replaces the entire resource representation at the target URI. Option B is wrong because POST is not idempotent; multiple identical POSTs can create multiple resources or trigger repeated side effects. Option C is wrong because DELETE is idempotent, since deleting an already-deleted resource leaves the server in the same state. Option E is wrong because PATCH is not guaranteed to be idempotent; its effect depends on the patch document and the resource's current state.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
GET is a safe method that must not change server state.
Why this is correct
GET is defined as safe under HTTP semantics, meaning it must not alter server state; it is intended solely for retrieval. This satisfies the stem's requirement for a true statement about REST methods, since safety distinguishes GET from state-changing methods such as POST, PUT, PATCH and DELETE.
- ✗
POST is idempotent, meaning multiple identical requests have the same effect.
Why it's wrong here
POST is non-idempotent: identical requests typically create multiple resources or trigger repeated side effects. It is tempting because POST bodies can look deterministic, but the server assigns new identities or appends state each time, so repeating the call changes the outcome; PUT and DELETE are the idempotent methods.
- ✗
DELETE is non-idempotent and each request may have a different outcome.
Why it's wrong here
DELETE is idempotent: repeating the same request leaves the resource in the same deleted state, so the outcome does not vary per call. It is tempting because DELETE removes data, which feels destructive and non-repeatable, but idempotency concerns the server state after identical requests, not the operation's severity.
- ✓
PUT is idempotent and replaces the entire resource at the target URI.
Why this is correct
PUT targets a specific URI and replaces the entire resource with the supplied representation; repeating the identical request yields the same end state, which is what makes it idempotent, unlike POST which creates a new resource each time.
- ✗
PATCH is always idempotent because it uses a patch document.
Why it's wrong here
PATCH is not guaranteed idempotent; a patch document may describe relative changes, so applying it twice can compound the effect. It is tempting because a fixed patch document looks repeatable, but idempotency depends on the operation's semantics, not the document format, and PATCH is explicitly non-idempotent by RFC 5789.
Go deeper
Related to this question
Learn chapter
Spine-Leaf and Software-Defined Network Architectures
Key term
REST API for Network Devices
A REST API for network devices is a set of rules that allows software applications to communicate with routers, switches, and firewalls using standard web methods like GET, POST, PUT, and DELETE over HTTP or HTTPS.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 350-401
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which two statements about REST API HTTP methods are true? (Choose two.)
medium- ✓ A.GET requests are idempotent and safe.
- B.POST requests are idempotent and safe.
- ✓ C.PUT requests are idempotent.
- D.DELETE requests are safe.
- E.PATCH requests are always idempotent.
Why A: Option A is correct because GET is defined by the HTTP specification as both a safe method (it does not alter server state) and an idempotent method (repeating the same request yields the same result without additional side effects), making it suitable for read-only retrieval of resources. Option C is correct because PUT is idempotent: issuing the same PUT request multiple times produces the same server state as a single request, since PUT replaces the target resource with the enclosed representation. Option B is incorrect because POST is neither safe nor idempotent—it typically creates a new resource or triggers a state change on each call, so repeated POSTs can produce multiple side effects. Option D is incorrect because DELETE is idempotent but not safe, as it modifies or removes server state. Option E is incorrect because PATCH is not guaranteed to be idempotent; whether it is depends on the patch document and implementation, so it cannot be stated as always idempotent.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.