hardMultiple Choice
PT0-002 Practice Question: During a vulnerability scan of a web application,…
During a vulnerability scan of a web application, a tester receives an HTTP response with a '405 Method Not Allowed' error when trying to use a PUT request. What does this indicate about the web server's configuration?
⚠ Common exam trap
Many exam-takers confuse a 405 Method Not Allowed with a 501 Not Implemented, mistakenly thinking the server lacks PUT support entirely, when in fact the server supports PUT but has been configured to deny it for that specific URI.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The server blocks the PUT method for that specific URI.
A 405 Method Not Allowed error indicates that the server recognized the PUT method as valid but has explicitly disallowed it for the requested URI. This is a server-level access control configuration, often enforced via web server directives (e.g., Apache's `<LimitExcept>` or IIS's request filtering) or application-level routing rules. The tester's PUT request reached the server and was processed, but the server's configuration prevented it from being fulfilled for that specific endpoint.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The server blocks the PUT method for that specific URI.
Why this is correct
The 405 (Method Not Allowed) status code specifically indicates that the requested resource exists, but the HTTP method used is not in its configured allowlist. The server's routing layer recognized the URI and rejected PUT, often because the endpoint is restricted to GET and POST. The response must include an Allow header enumerating permitted methods, so the tester should inspect that header to confirm PUT is blocked for this exact path, while it may be allowed elsewhere.
- ✗
The PUT method is allowed but the resource does not exist.
Why it's wrong here
If the target URI did not exist, a well-formed request would trigger a 404 (Not Found) instead of 405. In RESTful APIs, PUT is often used to create or replace a resource, so a missing resource typically results in 201 Created or 200 OK when PUT is permitted. The 405 response indicates the server identified the resource and considered the method inappropriate, which directly contradicts the idea that the resource is absent.
- ✗
The server does not support the PUT method.
Why it's wrong here
A 405 is resource-specific, not server-wide: the server may fully support PUT on other URIs but intentionally prohibit it on this one. If PUT were globally unsupported, the HTTP server would typically respond with 501 (Not Implemented) or a generic 400, depending on the framework. The Allow header returned with the 405 lists the methods the server recognizes for this URI, serving as proof that the method itself is not unknown.
- ✗
The request was malformed and rejected.
Why it's wrong here
A malformed HTTP request—such as invalid syntax, a missing Host header, or a corrupt content-length—is normally rejected with a 400 (Bad Request) during parsing, before routing logic executes. The 405 response shows the request was syntactically valid and reached the application layer, where the method was evaluated against the resource's permissions. Thus, the status code's precise method-based semantics eliminate the possibility of a malformed request.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.