Earlier quoted context omitted.
SMS 2FA isn't safe at least, and even NIST is deprecating it. The rest depends on dumb implementations, like Paypal allowing 2FA bypass with a change of the login link, or Google allowing 2FA bypass of all of its other methods by forcing you to use a phone number as "backup", which is to 2FA what secret questions were to passwords (their Achilles's heel).
Secret questions are horrible when they're predefined, and what's worse is when the options are also predefined (e.g. United Airline's website). However a secret question like "who did you have a crush on back in 5th grade" is limited to maybe 10 people the world who know and I'm comfortable with that (of course this changes with the over-publicising of our lives on social media). But I'm digressing and agree TOTOP 2…
Who quite possibly can be established from either your Facebook or your friends' Facebook (eg you have your friends list set private but a friend who posts on your wall doesn't).
Taking the "I had a crush on 'snail-fridge-running-spectrum'" line reduces the number who know the answer to on average less than 1(!).