CHFI Mobile and Malware Forensics Practice Question
During an Android forensic examination, the analyst uses ADB to run 'adb shell dumpsys batterystats --reset' before acquiring data. What is the MOST likely purpose of this command?
⚠ Common exam trap
EC-Council often tests the misconception that clearing logs is a benign or preparatory step, when in fact any command that modifies device state during acquisition violates forensic best practices and may be considered evidence spoliation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
This command is not recommended in forensic acquisition as it may destroy potential evidence
The 'adb shell dumpsys batterystats --reset' command clears the battery statistics logs on the device. In forensic acquisition, any command that modifies or deletes data on the device is considered destructive to evidence. The reset operation removes historical battery data that may contain timestamps and app usage patterns, which could be critical evidence. Therefore, this command is not recommended in forensic acquisition as it may destroy potential evidence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To clear battery logs that may contain evidence of app activity
Why it's wrong here
Resetting battery statistics via `adb shell dumpsys batterystats --reset` purges accumulated power usage, wake-lock records, and app-activity timestamps stored in batterystats.bin. An examiner's duty is to preserve potential evidence, not deliberately erase historical logs that could show when apps executed, whether the screen was on, or if background services remained active. Calling this a valid reason for clearing battery logs is therefore unsound, because the action destroys data and defeats the purpose of forensic acquisition.
- ✓
This command is not recommended in forensic acquisition as it may destroy potential evidence
Why this is correct
In Android forensic acquisition, state-changing commands such as `adb shell dumpsys batterystats --reset` are strictly avoided because they permanently delete historical battery and wake-lock data that may corroborate user behavior, malware activity, or spyware persistence. Sound methodology requires read-only or write-protected acquisition, and any command that writes to system files risks spoliation and breaks the chain of custody. Since resetting battery stats has no legitimate role in a defensible acquisition workflow, this command must not be recommended.
- ✗
To ensure the device is in a low-power state for safe extraction
Why it's wrong here
Resetting battery stats does not affect the device's current power state, discharge rate, or physical safety; it only erases a historical statistics file under `/data/system/batterystats.bin`. Safe acquisition is achieved by maintaining power, avoiding unintended boot or charging triggers, and using controlled extraction hardware, not by deleting logs. Thus, associating this destructive command with ensuring a low-power state is a false premise and indicates a misunderstanding of what the command actually does.
- ✗
To optimize device performance during imaging
Why it's wrong here
Forensic imaging is concerned exclusively with bit-for-bit preservation, so optimization steps that modify data, timestamps, or metadata are prohibited because they can compromise evidentiary integrity. Resetting battery stats has no measurable effect on imaging throughput, CPU load, I/O performance, or memory pressure, and therefore cannot optimize the extraction process. Invoking the command for performance reasons conflates system tuning with forensic acquisition and would incorrectly prioritize speed over evidentiary soundness.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.