Caching is one solution and it work fine, not perfect.
Another thing to consider is avoid hitting your api application with those requests.
You quite probably don't need authorization or any other business logic in that preflight. You can just catch any OPTION or OPTION+preflight headers in your proxy, webserver or balancer and handle it there.
You certainly don't want to handle them in Rails/Rack, nodejs, lambda, django, spring or such.
This makes them so much faster for users, and so much lighter for servers that the once per 2 hours cached request hardly is measurable, even.