Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • 10 Common Security Questions and Tips & Tricks to Mitigate Their Threat current page
Link copied

10 Common Security Questions and Tips & Tricks to Mitigate Their Threat

Jul 26, 2022
Author:
Morey Haber Headshot 2024
Morey J. Haber
Chief Security Advisor
Blog banner default
10 Common Security Questions and Tips & Tricks to Mitigate Their Threat
Morey Haber Headshot 2024
Morey J. Haber
Chief Security Advisor

Security Questions Can Pose a High Risk to Your Digital Identity

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

Every individual who has online accounts to access services or applications invariably has had to establish answers to security questions. We logon to a new bank account, social media service, or check out via our favorite online paid service, and we are required to enter initial responses to security questions. The purpose of these questions is to periodically re-affirm our identity, or to regain access if we forget our password, by providing our personal secret answers. But security questions can pose a high risk when it comes to identity security--especially nowadays, when threat actors are much more likely to log in than hack in.

Read on to learn more about why security questions pose such a high risk to identity security, and what we can do to protect our digital identities.

It is easier for a threat actor to log in versus hack in.

Morey J. Haber

What Are the 10 Most Common Security Questions?

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

Here are the ten most common security questions you'll be asked:

  1. In what city were you born?
  2. What is the name of your favorite pet?
  3. What is your mother's maiden name?
  4. What high school did you attend?
  5. What was the name of your elementary school?
  6. What was the make of your first car?
  7. What was your favorite food as a child?
  8. Where did you meet your spouse?
  9. What year was your father (or mother) born?
  10. What was the name of the street you grew up on?

Why Are Common Security Questions a Problem?

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

The problem with common security questions (and with our answers) is they become a liability when the results are leaked online, such as through a data breach, or become public knowledge via outlets like social media. Why? Because many (in fact, thousands) of sites potentially use identical security questions. The variation from site-to-site is low, and questions for each user frequently, and inevitably, overlap across their many accounts. This standardization of security questions creates a substantial, but unnecessary, risk.

The threat of common security questions is comparable to reusing passwords. Security pros, and end users, should know they should never reuse a password across accounts. This is because, if one account is compromised, the password is no longer secret and is associated with your credentials/identity and could be used for future attacks against any account you own that has the same (or similar) usernames. When passwords are re-used across dozens of accounts, the compromise of just one account could potentially lead to the compromise of all the other un-related accounts and ultimately your identity.

How Do I Make My Security Questions Stronger?

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

While we do usually have control over the passwords we choose, as individuals, we do not have the power to change the security questions these websites and services require. However, we can answer these questions in creative ways to make our accounts more secure and eliminates the threat of multiple accounts being compromised. Here is some basic guidance on how make security questions stronger:

1. Choose Different Security Questions Across Sites: As much as is possible, do not select the same security questions across multiple sites. Keep your selections unique when the site allows you to pick your own questions. This will help limit the fallout and compromise of other accounts if the security question/answer is ever leaked. This is especially important for public figures whose history may be a part of public record or biographies posted on websites. For example, we all know the city our favorite musician or actor was born in, right?

2. Use Special Characters in Your Answers: Do not answer security questions in plain English (or your native language). That is what is expected, but it’s a security misstep. Treat your answers like passwords and introduce complexity in your response and its characters. For example, let’s say I was born in Little Rock, Arkansas. The security question for, “what city where you born in” would require the response, “Little Rock”. Now, add some password complexity. The new entry could therefore be, “L!ttl3 r0ck”. This answer is more difficult to guess or crack through automated tools and provides a simple layer of obfuscation to protect your security question responses. And, if anyone ever asks, you can honestly state your mother’s maiden name does have numbers and symbols in it. Doesn’t yours? I think you get the point—a little obfuscation can go along way to secure your answers.

3. Use Fictitious Information: In many instances, the best course of action is to provide fictitious information to these questions to keep them unique. You could use a personal or enterprise password manager to populate the answer fields with password-like responses. Next, store each question and response in your password manager. For example, for an ecommerce site, you could create the entry “ecommercesite.com/question_birthcity” as the account and then enter a random, recommended password as the security response. This provides the secure storage you need in case of a password problem, while keeping your answers to same security question completely random and unique across sites and applications.

Why Mitigating the Use of Common Security Questions Is Important

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

Security questions were designed with the intent of strengthening identity validation for access to applications and websites, particularly in the case of a password issue or other fault. However, just as with password reuse, reusing security question and answer pairs across multiple sites has enabled threat actors to compromise many accounts associated with an identity. Typically, this requires a hacker to compromise a secondary application as well, like email or SMS texting, in order to pair a password reset with the knowledge of these security questions. Unfortunately, some websites and applications do not even go that far and knowledge of a security question answer is sufficient to compromise the account.

For IT and security professionals interested in a more rigorous and thorough examination of all the ways identities (corporate and personal) are at risk or under attack, and the best strategies for protecting them, learn more about: Identity Attack Vectors, a new book co-authored by Darran Rolls, CTO at SailPoint and myself, or learn more about the entire Attack Vectors series here. You can also watch our joint webinar on-demand: Deconstructing Identity as a Cyberattack Vector, or order the book to read it for yourself.

This blog has been updated since it was originally published on June 4, 2020.


Latest Posts
  • Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Jun 9, 2026 Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Blog
    6m
  • Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Jun 8, 2026 Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Blog
    5m
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
  • A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    May 26, 2026 A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    Blog
    3m
Related
  • Blockchain and Privileged Access Management
    Jan 16, 2018 Blockchain and Privileged Access Management
    Blog
    1m
  • Is Your Organization (Still) Cyber Insurable?
    Dec 1, 2021 Is Your Organization (Still) Cyber Insurable?
    Blog
    1m
Share this Article
  • Link
Tags
  • Account Access
  • Account Protection
  • Cyber Protection
  • Cyber Security
  • Data Breach
  • Data Security
  • Digital Identity
  • Identity Confirmation
  • Identity Protection
  • Identity Security
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.