CHFI OS and Network Forensics Practice Question
A forensic analyst is performing timeline analysis on a compromised system. Which tool is specifically designed to parse multiple log sources and create a super timeline?
⚠ Common exam trap
EC-Council often tests the distinction between disk forensics tools (Sleuth Kit), memory forensics tools (Volatility), network forensics tools (Wireshark), and timeline/log analysis tools (log2timeline), so candidates mistakenly choose a tool they recognize from other forensics domains without reading the specific requirement for parsing multiple log sources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
log2timeline
log2timeline (now part of the plaso framework) is specifically designed to parse multiple log sources—such as Windows Event Logs, syslog, web server logs, and file system metadata—and aggregate them into a single super timeline. This enables forensic analysts to correlate events across disparate logs for timeline analysis, which is exactly the requirement in the question.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Sleuth Kit
Why it's wrong here
Sleuth Kit analyses file system images and recovers artefacts, but it does not correlate disparate log sources into a unified super timeline. It suits disk-level examination, not multi-source event aggregation. The option tempts because Sleuth Kit includes a timeline feature, yet that timeline derives from file system metadata alone.
- ✓
log2timeline
Why this is correct
log2timeline parses disparate artefacts — event logs, file system metadata, registry hives — into a single bodyfile, which Plaso then sorts into a super timeline. This satisfies the requirement to correlate multiple log sources chronologically.
- ✗
Volatility
Why it's wrong here
Volatility examines memory images to extract processes, network connections and injected code, not to parse log files into a super timeline. It is correct for live-memory forensics, where volatile artefacts reside. The option tempts because Volatility outputs timestamps, yet those come from RAM structures rather than aggregated log sources.
- ✗
Wireshark
Why it's wrong here
Wireshark captures and dissects network packets; it produces no host-based super timeline from log sources. It is the right tool for traffic analysis and protocol troubleshooting, not forensic event correlation. The option tempts because Wireshark timestamps packets, but those timestamps never merge with file system or registry artefacts.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.