"There are no questions configured for you" - How can it be? I have followed exactly the steps described in OpenAM Administrator Guide.
I have explicitly keyed in "MacDonald" for the challenge question. What else can it be?
In the end, I gave up. I asked my colleague to provide a fresh pair of eyes. He took less than a minute!
OMG! That's not very obvious to me.
So ... if the Password Reset question is set and - most importantly - enabled, then the following is the expected flow:
PS: Password Reset feature is not related to Password Policy in Directory Server (aka OpenDJ / DSEE / AD).