Security questions and answers at a glance
A security question is a knowledge-based account-recovery prompt. Assume the question is public and protect the answer like another password.
| If you are… | Recommended approach |
|---|---|
| Choosing from an existing list | Select any prompt you can identify later, generate an unrelated random answer, and save both together |
| Allowed to write your own question | Use a clear label rather than a personal trivia puzzle; protect it with a random stored answer |
| Building a new application | Do not use security questions as an authenticator or password-reset factor |
| Recovering an account | Use a recovery code, registered authenticator, verified device, passkey, or official support process when available |
Important: NIST no longer recognizes knowledge-based authentication—commonly called security questions—as an acceptable authenticator because answers are often discoverable or drawn from small answer sets.
20 common security question examples
These sample security questions are shown so you can recognize them. A familiar prompt is not automatically a strong recovery method.
| Category | Example questions | Typical weakness |
|---|---|---|
| Family | What is your mother's maiden name? What is your oldest sibling's middle name? Where did your parents meet? | Public records, family knowledge, and social profiles |
| Childhood | What was your first pet's name? What elementary school did you attend? What was your childhood nickname? | Old posts, yearbooks, relatives, and a small likely answer set |
| Places | On what street did you grow up? In what city were you born? Where was your first vacation? | Property records, biographies, and location history |
| Firsts | What was your first car? What was your first job? What was the first concert you attended? | Ambiguous formatting and details shared in conversation |
| Favorites | What is your favorite movie? Who is your favorite author? What is your favorite food? What is your favorite sports team? | Answers change, are easy to guess, or appear online |
| School | What was your favorite subject? What was your teacher's last name? What was your school mascot? | Yearbooks, school websites, and former classmates |
| Personal dates | What is your anniversary? What is a memorable date? | Limited formats and information shared publicly |
Generate a random security answer
If an existing site requires a security question, the answer does not need to be factually related unless that site's instructions explicitly say otherwise. Generate an unrelated value, then save the selected question and exact answer together in your password manager.
Random security answer generator
Creates a mixed-case alphanumeric answer without ambiguous characters. Nothing is entered or transmitted.
Security question and answer examples
Use the generated value in place of the truthful personal fact. The examples below demonstrate the method; generate a different value for every real account.
| Selected question | Unsafe truthful answer | Safer stored-answer format |
|---|---|---|
| What was your first pet's name? | [actual pet name] | [unique random answer for this account] |
| In what city were you born? | [actual birth city] | [different unique random answer] |
| What was your first car? | [actual make and model] | [another unique random answer] |
Do not reuse one fabricated answer everywhere. Reuse turns that answer into a master secret: one breached account can expose every account protected by it.
What makes a strong security question?
If you must evaluate questions rather than replace the mechanism, prefer prompts whose answers have many possibilities, remain stable, apply to the user, are not public, and can be entered consistently. Avoid dates, family names, addresses, schools, favorites, document numbers, and anything routinely posted or recorded.
Even an uncommon or creative question can fail if the truthful answer is discoverable, forgotten, or reused. The random-answer workflow removes the connection to personal facts, but it still depends on secure storage and the site's protection of the answer.
Are security question answers case-sensitive?
There is no universal rule. A service may normalize capitalization and spaces, or it may require the exact original spelling, punctuation, and case. Save the answer exactly as entered and follow the site's current instructions. The generator uses no spaces or punctuation to reduce formatting ambiguity, but compatibility remains site-specific.
Security questions for password reset
NIST states that self-service password reset requires authentication of the account owner and that knowledge-based questions are not acceptable authenticators under its digital identity guidelines. Safer recovery designs use methods such as saved recovery codes, registered authenticators, verified devices, passkeys, or a controlled identity re-proofing process.
If you are an application owner maintaining a legacy question system, protect stored answers like passwords: normalize consistently, hash them with an appropriate password-hashing function, rate-limit attempts, prevent answer reuse, avoid revealing whether an answer was close, and plan migration to stronger recovery factors. OWASP recommends reviewing whether security questions are necessary at all.
Security question versus password hint
A password hint is displayed text intended to remind the account owner. A security question collects a secret answer and may influence an authentication or recovery decision. They solve different tasks and should not share the same personal clue. See the password hint examples guide for device-specific hint behavior.
Not the same as a business security questionnaire
A vendor security questionnaire asks an organization about controls such as access management, encryption, incident response, privacy, and compliance. It is an assessment document—not a personal account-recovery question. Banking identity-verification prompts and Canadian Interac e-Transfer questions also have distinct workflows and are not targeted by this page.
Sources and review date
This guide was reviewed on September 30, 2026. It provides examples and a local random-answer option without endorsing security questions as a modern recovery factor.