C

Privacy › Module 2 › Lesson 3

BeginnerModule 2Lesson 3/4

Account Recovery Security

Set up recovery options that help you regain access without helping attackers

15 min+38 XP3 quiz
Module progress3 of 4

Opening

Recovery is a security feature, not an afterthought

Lost phone, forgotten password, or locked out after travel—recovery paths decide whether you get back in in minutes or weeks. Weak recovery also gives attackers a back door. Balance convenience with controls that only you can satisfy.

1. Recovery Email and Phone

Most services let you add a recovery email and phone number. Use an address you still control and check regularly—not an old school account. For high-value accounts, the recovery email should itself have strong password and 2FA. Avoid using SMS-only recovery on your most sensitive accounts if SIM swap is a concern in your region.

2. Backup Codes and Authenticator Migration

  • Save backup codes at setup

    Store one-time codes in your password manager immediately. Each code usually works once.

  • Plan device upgrades

    Before replacing a phone, transfer authenticator accounts or add a second 2FA method temporarily.

  • Register a spare security key

    Many sites allow two FIDO keys—keep one on your keychain and one in a safe location.

3. Security Questions — Handle With Care

Classic security questions ask for your mother's maiden name or first school—answers often public on social media. Treat answers like passwords: use random strings stored in your password manager, not real facts. If a site forces weak questions, still protect the account with 2FA and unique passwords.

4. When You Are Locked Out

Use official recovery flows only—never share codes with someone who calls or messages you. Real support will not ask for your password or 2FA codes. Document account IDs and support URLs in advance for banking and email so you are not searching during stress.

Print one recovery sheet

For critical accounts, keep a single sealed envelope with backup codes and key serial numbers at home. Destroy and replace it when you rotate 2FA.

Knowledge Check

1

Recovery email addresses should:

Multiple choice

Knowledge Check

2

For security questions, a good practice is to:

Multiple choice

Knowledge Check

3

True or False: Legitimate support staff will never ask for your 2FA codes or password.

True or False

← Previous

Answer all 3 knowledge checks to continue. (0/3 answered)