Security Questions: Why Honest Answers Are Risky
Your mother's maiden name, first pet and first school can often be found online. Why honest security answers weaken your accounts, and how to use random answers stored in a password manager.

"What was the name of your first pet?" "What is your mother's maiden name?" "Which city were you born in?" Security questions were meant to protect your account if you forget your password. The trouble is that honest answers are often easy to find, guess or trick out of you, which turns a safety feature into a back door.
Why honest answers are risky
- They are often public. Birthplaces, schools, pets and family names appear on social media, obituaries, family trees and old posts.
- They can be guessed. Favourite colours and first cars come from a short list.
- They are harvested by quizzes. "Your superhero name is your first pet plus your street!" See social media quizzes.
- They never change. Once your mother's maiden name leaks, it is leaked forever.
- They are reused across many services, so one leak affects many accounts.
Current guidance, including from NIST, discourages relying on this kind of knowledge-based question for security.
The better approach: random answers
A security answer does not have to be true. It only has to be something you can produce and others cannot.
| Question | Honest answer (risky) | Random answer (safer) |
|---|---|---|
| First pet's name | Buddy | velvet tractor seven |
| Mother's maiden name | (findable online) | orbit pickle lantern |
| City of birth | (on your profile) | marble cactus drum |
These are examples only; create your own.
How to manage random answers
- Store them in your password manager, in the notes for that account. See how to set up a password manager.
- Make them pronounceable (a few unrelated words) in case you need to say them to a support agent.
- Use a different answer for each service.
- Update old accounts as you go, starting with email, banking and mobile networks.
Better still, use stronger recovery. Where services offer recovery codes, authenticator apps or passkeys, use them. See email recovery settings explained.
Watch out for social engineering
Scammers call pretending to be your bank or network and ask "security questions" to "verify" you. Genuine organizations may ask questions when you call them, but be cautious when someone who called you asks for this information. Hang up and call back on the official number.
Received a message asking you to "confirm" security answers? Paste it into CyberWatch AI Scan for a free check.
For more ways to protect your accounts, read our complete guide to identity theft and account security.
Frequently asked questions
Is it okay to give false answers to security questions?
Yes. The point of a security answer is that only you know it. A random answer stored in your password manager is far safer than a true fact others can find.
What if I need to say my answer over the phone?
Use a random but pronounceable answer, such as a few unrelated words, so you can read it out if a genuine support agent asks.
Should I remove security questions if I can?
If a service offers stronger recovery methods, such as recovery codes, passkeys or authenticator apps, use those. Keep any remaining security answers random.
Sources
- NIST SP 800-63B: Authentication and Lifecycle Management, US National Institute of Standards and Technology
- Social media: how to use it safely, UK National Cyber Security Centre
- Protect Your Personal Information From Hackers and Scammers, US Federal Trade Commission


