Courseiva
mediumMultiple Choice

200-901 Practice Question: A company has a web application running on Cisco…

A company has a web application running on Cisco DNA Center. The application uses OAuth 2.0 for authentication with an external identity provider (IdP). Recently, users have reported that they are being logged out unexpectedly after a few minutes of inactivity, even though the IdP token has a 1-hour expiration. The application developer wants to maintain usability while keeping security controls. What is the most likely cause and solution?

⚠ Common exam trap

Cisco often tests the distinction between token expiration and session timeout, where candidates mistakenly focus on token refresh or IdP configuration instead of recognizing that the application's session management is the root cause.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The application session timeout is shorter than the token lifetime; align the application session timeout to the token expiration or implement silent token refresh

The most likely cause is that the application's session timeout is set to a shorter duration than the OAuth 2.0 token's 1-hour expiration. When the application session expires, the user is logged out even though the IdP token is still valid. The solution is to align the application session timeout with the token expiration or implement silent token refresh using a refresh token, which allows the application to obtain a new access token without user interaction, maintaining usability while preserving security.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The application session timeout is shorter than the token lifetime; align the application session timeout to the token expiration or implement silent token refresh

    Why this is correct

    The application's own session cookie expires before the one-hour IdP token, forcing re-authentication despite a valid token. Aligning the session timeout with token lifetime, or using silent refresh via a hidden iframe or refresh token, preserves usability while retaining security controls.

  • ✗

    The application is not properly validating the token expiry and needs to refresh tokens proactively

    Why it's wrong here

    Proactive refresh addresses token lifetime, yet the reported symptom is logout after minutes of inactivity while the token remains valid for an hour, so expiry validation is not the trigger. Refresh logic is correct when tokens genuinely expire mid-session and the client must obtain new ones without re-prompting.

  • ✗

    The IdP is configured to log out users automatically after 5 minutes; reconfigure IdP session settings

    Why it's wrong here

    A five-minute IdP session timeout would end the session at the identity provider, but the stem states the token expires in one hour, so the IdP is not enforcing that short window. Adjusting IdP session settings is right when the IdP itself imposes the premature logout.

  • ✗

    The OAuth 2.0 access token is set to expire in 5 minutes; increase it to 1 hour

    Why it's wrong here

    The stem states the IdP token already lasts one hour, so shortening the access token to five minutes is a separate, deliberate setting; raising it to an hour would extend exposure and still not address refresh-token handling. Access-token lifetimes are configured for short-lived API authorisation, which is correct when minimising replay risk matters more than session continuity.

About these practice questions

Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.