If you make sure you don't use simple logic questions and questions that cant easily be queried with a search engine, I'm not saying it wont help (for a while)
The software is also able to gather and decipher artificial intelligence such as security questions (i.e. what is 2+2?) often used by forums upon registration. Since the latest version of XRumer, the software is capable of collecting such security questions from multiple sources and is much more effective in defeating them.
Helper program Hrefer is also included. This software is used to automatically parse results from search engines including Google, Yahoo, Bing and Yandex for forums and blogs that can then be used as a target list for the main XRumer application.[citation needed]
According to The Register, as of October 2008, XRumer can defeat CAPTCHAs of Hotmail and Gmail.
http://en.wikipedia.org/wiki/XRumer
One of Xrumers "show-offs" is that it contains a list of high PR XenForo sites, this being one of them
If those sites started to no longer work for Xrumer, it wouldn't take much to learn the QA answers (Xrumer already learns many QAs)
a quick link to the latest version of XRumer:
http://ixrumer.com/xrumer/
You'll notice they talk about
Those who read topic "How to teach Xrumer to new text captcha" – know that our software is able to pass such protection like “What is current year?”, “2+2=?” etc.
Who didn’t read this topic we recommend to read it:
In that topic is described how to train XRumer to new protections by editing textcapctha.txt. With release of version 7.07 this process becomes easiest. Also is created mechanism of collective teaching of text CAPTCHA. That means all results of training are stored on our server and after are distributed to all our customers. Due to this system success rate is increased.
QAs are not the way forward, neither are common CAPTCHAs... they will learn from these / train against them
Custom CAPTCHA (your own CAPTHCA method or the free resource
CustomImgCaptcha ), the
stop forum spam method (coming in 1.3) to prevent known bots, hidden honey pot fields (such as FoolBotHoneyPot) and customisations of your registration pages that you can do your self (or also available with FoolBotHoneyPot), and validating the first few posts will all help and last a lot longer as methods
With QAs, you might find you will need to update them every few months to keep beating back the bots
There is another very big problem with QA's, but unfortunately I can't really talk about it until a fix is made