I use random strings and store them in a Passwordsafe db. Ever since the Sony PSN hack which IIRC did include secret questions and answers.
(I may be mistaken, but I do know it was absolutely the last time I gave a company true information for security questions).