Another simplier solution we have implemented is simply asking the helpdesk technician to complete the self service password reset as the user on the phone. If that person cannot answer all of the questions correctly, they simply don't get a password reset and their manager has to call the helpdesk to get the user's password reset.
Being able to actually see the questions and answers for a user would avoid typos in the current workaround. Thanks!