A vital and important question. There are varying opinions on this, but one of the best guides around can be found here:
The weak link in the security chain with Strongbox is always going to be the master password. It can be difficult to come up with one, but it’s always better to use a multiple word phrase instead of a single word and to thrown in some numbers too. The above guide should help.
Always, always, ALWAYS remember your master password. There is no getting into your database without this. No one can.