The format of security question

Is it considered insecure that we let users to set an answer 4 to 8 characters string?
I am thinking whether hacker would be able to brute force the answer by trial and errors.
Are there any rate limit in attempts to enter a backup share?
Thank you!