I agree with your security team. The "security question" is not secure on its own: cities can be found over ip, names can be googled and nicknames of pets can be guessed.

However, you could combine both methods: first send the mail, and when the user clicks the link, ask the question. This way you would add at least a bit more security to the procedere. Also think about a lock (e.g. 12 hours) after three bad attempts to ensure bruteforcing isn't possible.

Answer from licklake on Stack Exchange
🌐
Okta
okta.com › blog › identity security
Security Questions: Best Practices, Examples, and Ideas | Okta
Typically, these security questions and answers are used for self-service password recovery—inputting the correct answer verifies the user and allows them to reset their password—though you can also implement security questions as an additional authentication factor for logins.
🌐
Microsoft Support
support.microsoft.com › en-us › account-billing › set-up-security-questions-as-your-verification-method-3d74aedd-88a5-4932-a211-9f0bfbab5de8
Set up security questions as your verification method - Microsoft Support
If you don't see the security questions ... to choose another method or contact your administrator for more help. Administrator accounts are not allowed to use security questions as a password reset method....
🌐
Avatier
avatier.com › home › blog › 7 best practices for password reset questions
7 Best Practices for Password Reset Questions
April 9, 2020 - Users who enter the answers to security questions twice are more likely to remember them. 6) Expire Password Reset Questions For High-Risk Access
🌐
Journal of Accountancy
journalofaccountancy.com › home › magazines › online security: the password-recovery questions you should be answering
Online security: The password-recovery questions you should be answering
March 1, 2018 - To combat the more simplistic nature of security questions administrators often ask, end users might consider protecting themselves further by providing random answers that cannot be researched or guessed. In effect, I am suggesting that your answers be more random so they act more like a password. For example, instead of providing your mother’s ­actual maiden name, you might provide the made-up name Aphrodite1234!, which resembles a password more so than a name.
🌐
OWASP Cheat Sheet Series
cheatsheetseries.owasp.org › cheatsheets › Choosing_and_Using_Security_Questions_Cheat_Sheet.html
Choosing and Using Security Questions - OWASP Cheat Sheet Series
The combination of a password and security questions does not constitute MFA, as both factors as the same (i.e. something you know).. Security questions should never be relied upon as the sole mechanism to authenticate a user. However, they can provide a useful additional layer of security when other stronger factors are not available. Common cases where they would be used include: Logging in. Resetting a forgotten password.
🌐
NordVPN
nordvpn.com › blog › security-questions
How to choose the best security questions | NordVPN
May 7, 2025 - It’s one of the online authentication methods for account recovery and an extra layer hackers need to break to get in. But don’t rush it, because not all questions can guarantee security. Read on to learn about the most common security questions and how to choose a good one. ... Many platforms ask you to choose a security question, which you will need to answer when logging in or resetting your password...
🌐
Reddit
reddit.com › r/lastpass › sites that allow security question password resets
r/Lastpass on Reddit: Sites that allow security question password resets
January 8, 2022 -

Can anyone direct me to a list of sites that allow password resets through security questions only? I would like to check my sites against those and put in unique responses for any sites I care about, as I assume (100%) that my true security question answers are available for any moderate hacker or even just an averagely persistent person.

Find elsewhere
🌐
VeePN
veepn.com › home › best security questions: selection criteria and examples
Best Security Questions: Selection Criteria and Examples | VeePN Blog
May 21, 2025 - 1.Criteria for choosing good security questions 2.Basic types of secure questions 3.Recommendations for choosing the best security questions 4.Examples of efficient and inefficient security questions 5.What is the reason for the need to use a VPN? Entering correct security answers to your question helps protect your website from critical changes. Even if attackers have taken possession of the password from the control panel, they will not be able to remove the module, change the password or security settings without knowing the correct answer to the security question.
🌐
Full Scale
fullscale.io › blog › best-security-questions
Best Security Questions for Robust Protection (Examples)
Discover all the latest in technology, trends, innovation, IT news, hot skills, and culture from Full Scale's official blog.
Top answer
1 of 5
13

Hi and thanks for reaching out. My name is William. I'm a Windows technical expert. I'll be happy to help you out today.

It is not possible to reset security questions. However, If you cant recall the original pw you set the device up with initially, then you will nee to create a secondary local admin account to reset the pw for your primary account. To do this, you will need to create Windows 10 boot media (on another computer) and boot from it as if you were going to install Windows, but will instead use this environment to create the new admin account. To create Windows 10 installation boot media, see this Microsoft article: https://www.microsoft.com/en-us/software-downlo...

Alternatively, if you have Windows 10 DVD, you can boot from that, too.

After booting from the boot media, go to the section "Create a New User to Save Account Files" in this guide: https://www.howtogeek.com/222262/how-to-reset-y...

Note, the above link assumes your system drive is letter D:. If the command fails, then use C: in place of D: for the copy command.

2 of 5
3

Hi and thanks for reaching out. My name is William. I'm a Windows technical expert. I'll be happy to help you out today.

It is not possible to reset security questions. However, If you cant recall the original pw you set the device up with initially, then you will nee to create a secondary local admin account to reset the pw for your primary account. To do this, you will need to create Windows 10 boot media (on another computer) and boot from it as if you were going to install Windows, but will instead use this environment to create the new admin account. To create Windows 10 installation boot media, see this Microsoft article: https://www.microsoft.com/en-us/software-downlo...

Alternatively, if you have Windows 10 DVD, you can boot from that, too.

After booting from the boot media, go to the section "Create a New User to Save Account Files" in this guide: https://www.howtogeek.com/222262/how-to-reset-y...

Note, the above link assumes your system drive is letter D:. If the command fails, then use C: in place of D: for the copy command.anks E

thanks for the quick response WilliamDZ. I will give it a try and let you know how I go.  Cheers

🌐
Quora
quora.com › What-are-the-most-common-security-questions-to-retrieve-a-users-password
What are the most common security questions to retrieve a user's password? - Quora
Answer (1 of 14): Security question are gradually going away as new and better authentication systems come into play. Meanwhile, many online tools are still using security questions to retrieve credentials or verify identity. There are a lot of security questions, most are bad and shouldn’t be u...
🌐
Designingsecuresoftware
designingsecuresoftware.com › home › secret questions for password reset
Secret Questions for password reset - Designing Secure Software
July 11, 2024 - Questions should be designed to have answers unique to the user they won't forget, not known to attackers. Password reset requires answering the questions with the same answers in order to regain access.
🌐
Google Support
support.google.com › accounts › thread › 150665812 › i-forget-password-and-security-question-s-answer
i forget password and security question's answer - Google Account Community
Skip to main content · Google Account Help · Sign in · Google Help · Help Center · Community · Google Account · Terms of Service · Submit feedback · Send feedback on
🌐
Case Western Reserve University
case.edu › utech › help › knowledge-base › passwords › password-reset-questions-kba-100103
Password Reset Questions - KBA 100103 | University Technology, [U]Tech | Case Western Reserve University
April 19, 2018 - Select a security question from the Question dropdown box and enter the answer into the Answer and Re-Type Answer fields. Finally, click on the Submit button. If you find you can neither log in with your password nor change your password using the UTech Password Change page, someone may have guessed and reset your password in order to gain access to your CWRU Network account.
🌐
Optimal IdM
optimalidm.com › home › news › security question best practices
Protecting Your Data: Best Practices for Security Questions
May 21, 2024 - Security questions offer secure solutions for retrieving and resetting passwords.
🌐
Mercer
it.mercer.edu › faculty › security › password_self_service.htm
Password Self-Service | Faculty | MU Information Technology
Select the Forgot my password link. Enter the characters in the picture or the words in the audio and click Next. Choose text or call my mobile phone for verification step 1 and follow the steps. Answer three security questions for verification step 2 and click Next.
🌐
Quickbase Help
helpv2.quickbase.com › hc › en-us › articles › 4570395283348-Reset-security-question
Reset security question – Quickbase Help
Click the Reset security question button in the user details. (Note:This control will not appear if users are not required to answer their security question during password reset.)
🌐
Proton
proton.me › blog › security-questions-flaws-solutions
Are security questions terrible for account security? | Proton
February 27, 2025 - Security questions are meant to help reset passwords, reopen locked accounts, and ultimately protect your digital spaces from attacks or breaches, but such safeguarding is widely considered flawed and unreliable(new window).
🌐
JustAnswer
justanswer.com › computer › 60f20-change-security-question-i-can-t-remember.html
How to Change Security Questions: Expert Answers & Solutions
To reset security questions, first attempt account recovery via the platform’s 'Forgot Password' or 'Account Recovery' options. Verify your identity using linked email or phone number. If unsuccessful, contact customer support directly with proof of identity.