I feel like security questions are supposed to be part of the
third pole of the "what you know, what you have, what you are" triangle. You lost the thing you have, or you forgot the thing you knew. The way to get it back is to prove that you are the things you are.
Because of this, memories (mother's maiden name, high school you went to, etc.) are meaningless for security questions. These are effectively more passwords.
The effective kind of security questions look something more like "how many moles do you have on your entire body" or "what is the position (in dental notation) of the tooth you cracked when you were 23". These are pieces of information you can derive by examining yourself, which you took the time to derive once (when you set up the question) and could, at any point, take the time to derive again--but which anyone else, to impersonate you, would basically have to have you tied up, naked, and incapacitated to figure out.
Fingerprints, DNA samples, etc. also work for a 3FA, but only if taken interactively (that is, with a tester standing there watching you provide them.)
Combining the two methods--having a battery of little assays, some self-derived, some assisted--works better, though, since any one of these dimensions might drift over time (you might get a new mole!) but together they should form a reasonable "profile" of you.
---
A tangent: it'd be neat if there was a company that let you register a set of these tests to enable the release of something like a one-time private signing key held in escrow. You could just give these other third-parties that want 3FA questions the public-key fingerprint (never actually having had possession of the private key yet), and then if they ever need it, contact the challenge company to get your key unlocked and "re-notarize" your profiles with it.