DataJive

Security Questions Are Weak: How to Answer Them Safely

By DataJive Editorial Team · Updated Oct 4, 2026 · 1 min read
Security Questions Are Weak: How to Answer Them Safely

Security questions like “What was your first car?” were meant to help you recover an account. Today they are often the weakest link, because the answers can be found on social media, in public records or guessed.

Why they are weak

  • Many answers are public or easily researched.
  • Answers are often limited to a small set of common choices.
  • Family members and acquaintances may know them.
  • The same answers are reused across sites.

A safer approach

Treat the answer as a second password. Instead of the truth, enter a random string or a long made-up phrase, and store the question and answer in your password manager.

Examples of a good answer

Instead of “Fluffy”, store something like “orbit-pencil-granite-42”. It does not need to make sense, it just needs to be unguessable and saved.

Use better recovery options

Where a site offers authenticator apps, recovery codes or a hardware key, choose those over security questions. If you can, turn the questions off.

Key takeaway: Never answer security questions truthfully. Generate random answers and save them in your password manager.

DJ
DataJive Editorial Team
We research and test security and privacy tools, and explain them in plain language. Content is for information only.

Related guides