Mental model
HTTP is how your browser, your Python script, and curl all talk to web servers. One side asks (a request); the other side answers (a response). Each side has three parts:
- A first line (method + URL for requests; status code + reason for responses).
- A set of headers (metadata: content type, auth, caching).
- An optional body (JSON, HTML, bytes).
Cisco objectives 2.4 and 2.6 test your ability to read HTTP responses: understand status codes, pick information out of headers, parse the body. Objective 2.1 asks you to construct requests. This topic covers everything you need.
Methods
| Method | Purpose | Idempotent? | Body on request? |
|---|---|---|---|
GET | Read a resource | Yes | Rare |
POST | Create a resource or submit data | No | Usually |
PUT | Replace a resource entirely | Yes | Yes |
PATCH | Partially update a resource | No (usually) | Yes |
DELETE | Remove a resource | Yes | Rare |
Idempotent = running the same request twice has the same end state as running it once. GET and DELETE and PUT are idempotent. POST is not (two POSTs usually create two resources).
Cisco objective 2.1 asks you to pick the right method given a verb in English:
- “List all devices” → GET
- “Add a device” → POST
- “Replace this device’s full config” → PUT
- “Change the hostname of this device” → PATCH
- “Delete this device” → DELETE
Status codes
Three digits. First digit is the family.
| Family | Meaning | Examples |
|---|---|---|
| 1xx | Informational (rare in network APIs) | 100 Continue, 101 Switching Protocols |
| 2xx | Success | 200 OK, 201 Created, 204 No Content |
| 3xx | Redirect; follow the Location header | 301 Moved Permanently, 302 Found, 304 Not Modified |
| 4xx | Client error — fix your request | 400 Bad Request, 401 Unauthorized, 403 Forbidden, 404 Not Found, 405 Method Not Allowed, 409 Conflict, 429 Too Many Requests |
| 5xx | Server error — not your fault, retry later | 500 Internal Server Error, 502 Bad Gateway, 503 Service Unavailable |
Memorise these common ones for the exam:
- 200 OK — your GET worked. Payload is in the body.
- 201 Created — your POST worked and made a new resource. Location header has its URL.
- 204 No Content — your DELETE worked. No body.
- 400 Bad Request — your JSON is malformed or missing a field. Read the error body.
- 401 Unauthorized — you forgot or sent wrong auth.
- 403 Forbidden — auth was fine but you lack permission.
- 404 Not Found — the URL does not match any resource.
- 409 Conflict — your change clashes with current state (e.g., VLAN already exists).
- 429 Too Many Requests — rate limited. Back off per Retry-After header.
- 500 Internal Server Error — the server crashed. Not your fault.
Objective 2.4 asks you to explain status codes; 2.5 asks you to troubleshoot given one. The pattern is always:
- First digit? 4xx = me. 5xx = them. 2xx = all good.
- Specific code? Match to the table above. Read the body for details.
Request shape
POST /devices HTTP/1.1
Host: api.example.com
Authorization: Bearer eyJhbGci...
Content-Type: application/json
Content-Length: 42
{"name": "sw3", "ip": "10.0.0.3"}
Line 1 — method, path, protocol. Lines 2 to 5 — headers. One per line, Name: value. Blank line — separator. Rest — body (optional). Length matches Content-Length.
Response shape
HTTP/1.1 201 Created
Content-Type: application/json
Location: /devices/42
Content-Length: 29
{"id": 42, "created": true}
Same shape, status line instead of request line. Location header points at the new resource (because this was a POST that created something).
Headers that matter for CCNA Automation
| Header | Direction | What it means |
|---|---|---|
Content-Type | Both | Format of the body: application/json, application/xml, text/html |
Accept | Request | Formats you want back. Server picks one and sets Content-Type accordingly |
Authorization | Request | Credentials: Basic ..., Bearer ... |
User-Agent | Request | Identifies your client (curl, Python requests, browser) |
Content-Length | Both | Byte length of the body |
Location | Response | URL of the newly-created or redirected-to resource |
Retry-After | Response | Seconds to wait before retrying (returned with 429 and 503) |
WWW-Authenticate | Response | Auth scheme the server expects (returned with 401) |
Request body
Almost always JSON for modern APIs. For an older or SOAP-style API, XML. Form-encoded (application/x-www-form-urlencoded) still shows up for HTML form submissions.
For CCNA Automation, you will see JSON bodies in nearly every example.
Hit a real-looking REST API with curl
12 scripted steps. GET a 200. See a 404. Read response headers with -i. POST a device with a JSON body. Watch 401 vs 200 as you add an Authorization header.
Open the lab →FAQ
What is the difference between PUT and PATCH? PUT replaces the whole resource; the body must contain every field (missing fields are cleared). PATCH applies a delta; only the fields you include change. PATCH is newer and most modern APIs prefer it.
Why is my browser only using GET and POST? HTML forms only support GET and POST. The others are available to JavaScript (fetch), curl, Python requests, and other HTTP clients.
What is an “idempotent” method really? Running the request N times leaves the server in the same final state as running it once. Important when you retry on timeouts: safe for GET/PUT/DELETE, dangerous for POST.
Does HTTPS change any of this? No. HTTPS is HTTP wrapped in TLS. Methods, status codes, headers, body are identical; everything between client and server is encrypted.
What is HTTP/2 or HTTP/3? Do I need to know them for 200-901? No. The exam targets the semantic layer (methods, codes, headers). The transport (1.1 vs 2 vs 3 vs over QUIC) does not change the exam content.
