Thought about this a moment before answering This is on a test site (running 4.0.2.), same server, and is not happening at the live site (running 4.0.1.)
Yes, however 4.0.2 makes changes to the urls. specifically adding special chars such as ? into them; your urls on 4.0.1 wouldn't have this. The url could be triggering mod_security BECAUSE of the new ? in the url.
goto diagnostics and hit the check for problematic webserver modules. See if it detects mod_security.