Yes, I'd know something was up, and I wouldn't be able to do anything about it. However, the more important implication is that they have a way into our accounts that does not involve any authentication on our end. Maybe there could be two passwords that get into the account. No way for us to tell. If we are to have any assurance of privacy beyond Tim Cook's promise that they don't collect data, that password reset method would have to not exist, among other things.
I'm still missing your point. Doesn't the password reset require answering the security questions?