As far as I am able to surmise the security checks are genuine. I nervously followed through on the security questions and designated a "rescue email address" in the event that I had forgotten the answers to the security questions!
This action resulted in an email incoming me to follow a link to confirm that it really was me who had designated that email address.
I analysed this link using the Internet Whois utility to confirm that the link domain that I had to follow really belonged to Apple! The link domain was id.apple.com. This domain then linked to verification subnet information. I confirmed that the domain belonged to Apple and then ran a traceroute command to check out the server hops. This also helped confirm that this was a genuine Apple email and a genuine verification request running via apple file servers.
Only when I had completed these checks did I run the link and confirm that the email address belonged to me and was genuine. The apple response message was to confirm that my rescue email address was now linked to my apple ID.
It really would help if someone would get off their backside at Apple and make an official announcement about this stuff.
The result of their (mis) management of this issue is to sow the seeds of fear, uncertainty and doubt into the minds of apple user base. This is not good of Apple and it certainly is not good for those of us who form their user base.