I think you may have missed my point: users are dumb and cannot be trusted to pick their own security questions.
It really depends on the audience you are expecting. If you are expecting information security experts or privacy enthusiasts it's probably safe to say they know enough to not do the "What's my favorite band?" kinda thing.
But if you are building services for the average user then you do not give them any choices that could make them less secure if they don't do it right.
So always encourage passphrases and a good password manager, U2F and TOTP based authentication apps.
We're a place where coders share, stay up-to-date and grow their careers.
We strive for transparency and don't collect excess data.