I have my challenge response set up so users need to set up 2 questions
& answers, plus the default one.

I also have it set up to ask one random question when the password is
forgotten, however it always seems to ask all 3 and they all 3 need to
be correct to get authenticated.

Running client 4.91sp4 on xp pro in an edir 885 tree.