What should I put for security questions like my first pet's name?
Why honest answers are the weakness, the two workable approaches, and how to handle the questions a bank will read out to you on the phone.
- Difficulty
- beginner
- Time
- 6 min
- Read
- 3 min
- Safety
- caution
Short answer
Do not answer truthfully. Generate a random answer for each question and store it in your password manager alongside the account, the same way you store a password. Where a human will read the question aloud — a bank on the phone — use a consistent invented answer you can say out loud rather than a random string.
Security questions were designed when nobody's mother's maiden name was searchable. Most of the standard set is now public information, guessable from a social profile, or has a small enough range of likely answers to be brute-forced. Treating them as facts about you is the mistake.
Safety
Step by step
- Recognise which questions are worst.Mother's maiden name, town of birth, first school, first car, favourite colour, favourite football team. Several are matters of public record, one is on your birth certificate, and the rest have very few plausible answers.
- Use random answers for anything typed.Where you will type the answer into a web form, generate it like a password and store it in the manager in the notes field for that account. There is no requirement anywhere that an answer be true.
- Use a memorable invented answer for anything spoken.Banks read these out on the phone and you have to say the answer aloud. A random string is unusable there. Instead choose one consistent invented set — a false maiden name, a false first school — that you can remember and say naturally.
- Never reuse an answer across services.The same reasoning as passwords. An answer disclosed in one breach becomes a key to the others if it is shared.
- Record what you used.In your password manager, on the entry for that account. An invented answer you cannot recall is worse than a truthful one, because it locks you out.
- Prefer a proper second factor where it is offered.Where the service lets you choose between security questions and an authenticator app or a passkey, take the app or the passkey. Security questions are a weak substitute retained for compatibility.
- Audit the answers you gave years ago.Older accounts, particularly banking and email, often still have truthful answers set. Change them to invented ones next time you are in the security settings.
- Be careful about what you publish.Social media quizzes asking for your first pet, your street name or your first car are collecting exactly this set. Not all of them are innocent.
Tips
- If a form insists on a plausible-looking word, use an unrelated real word rather than a random string — "Wolverhampton" as a first school is memorable, storable and not true.
- Where a bank sets up a spoken password, choose something with no connection to you at all, and never one you use as an actual password.
- Do not let a family member's honest answer become your security question; shared family facts are the easiest of all to discover.
Common mistakes
- Answering truthfully because it feels like a form — It is a credential, not a survey. Truthful answers to standard questions are among the easiest credentials to research.
- Using the same invented answer everywhere — It becomes a single reusable key, with all the problems of a reused password.
- Not writing down what you invented — The lockout it causes is real and account recovery is slow. Store it with the account.
Questions people ask
Is it allowed to give false answers?
Yes. These are authentication credentials, not declarations. No provider requires them to be factually true, and security guidance recommends treating them as secrets.
What if the bank asks me the question on the phone?
Use an invented answer you can say aloud and remember consistently. Record it in your password manager so it is retrievable.
Are security questions being phased out?
Gradually, in favour of authenticator apps and passkeys, but they remain widely used for account recovery. Where you can choose something stronger, do.