Free Snowflake SnowPro-Core Actual Exam Questions - Question 4 Discussion
Authentication (MFA) token valid for?
D imo. The name ALLOW_CLIENT_MFA_CACHING suggests a longer cache time to reduce repeated prompts, so 8 hours fits better than shorter intervals like 2 or 4 hours.
C, since 4 hours is often the default cache time in similar MFA settings.
B. I’m with those saying 2 hours. It’s a good compromise between user convenience and keeping the MFA token from lingering too long. Anything shorter might get annoying, and longer would risk security more. Also, this seems to be a pretty standard default in several systems I've worked with.
Option B, since two hours balances convenience and security well in MFA caching.
B/C? I’m ruling out A since 1 hour seems too short for most MFA caching setups, and D feels like it might be pushing it too long security-wise. Between B and C, 2 hours is a common middle ground in a few systems I’ve seen, but 4 hours also makes sense if they want to reduce MFA prompts more aggressively. Without specific platform details, I’d pick B just because it balances usability and security better for cached MFA tokens.
A imo, since some systems default to a 1-hour cache to keep MFA fairly tight without annoying users too much. Longer times feel riskier for security.
I’m going with C here. Four hours feels like the sweet spot for caching MFA tokens — long enough to avoid constant prompts but not so long that it risks security. One or two hours might be too short for practical use, and eight hours seems a bit excessive for most secure environments. So, C makes the most sense based on what I know about typical MFA caching durations.
Maybe B on this one. Two hours feels like a reasonable middle ground that some systems use to avoid too frequent MFA prompts but still keep security tight. Eight hours sounds a bit long for MFA caching since it could expose you to more risk if a token gets compromised. Plus, 4 hours is common but some setups might opt for a shorter window like 2 hours to be safer yet practical. So I’d go with B unless the question specifically points to a long-duration setting.
A looks unlikely since 1 hour is pretty short for caching MFA tokens. Between these, 4 hours (C) seems like a standard compromise to reduce repeated logins without going too long.
Option B makes sense since 2 hours is a common default for token caching in many systems, balancing security and convenience better than longer times.
C imo, because 4 hours is the usual caching duration for MFA tokens.