Questions
Questions

FIT5032_S2_2025 Sample Quiz

Single choice

A developer has implemented a custom API using Firebase Cloud Functions to serve specific data. This API is designed to handle GET requests for public data. A security audit flags a concern about how the API handles unsupported HTTP methods, such as a PUT request. According to best practices for API security and error handling, which response is the most appropriate when a PUT request is received at this GET-only endpoint?

Options
A.a. Return a 500 Internal Server Error, as an unexpected request method indicates a server-side problem.
B.b. Return a 200 OK status with an empty response body, as no data was modified.
C.c. Return a 405 Method Not Allowed status, explicitly indicating that the PUT method is not supported.
D.d. Return a 404 Not Found status, to avoid exposing internal logic about supported methods to potential attackers.
Question Image
View Explanation

View Explanation

Verified Answer
Please login to view
Step-by-Step Analysis
Let’s break down what the question is asking: when a PUT request arrives at a GET-only endpoint, which response best aligns with API security and proper error handling practices? Option a: Return a 500 Internal Server Error, as an unexpected request method indicates a server-side problem. - This is not appropriate because an unsupported method is a normal, anticipated scenario, not a server fault. A 500 implies the server crashed or encountered an unexpected condition, whic......Login to view full explanation

Log in for full answers

We've collected over 50,000 authentic exam questions and detailed explanations from around the globe. Log in now and get instant access to the answers!

More Practical Tools for Students Powered by AI Study Helper

Join us and instantly unlock extensive past papers & exclusive solutions to get a head start on your studies!