CHFI OS and Network Forensics Practice Question
A forensic analyst needs to create a timeline of file system activity from a disk image. Which tool is specifically designed for this purpose and can parse various artifacts such as registry, prefetch, and log files?
⚠ Common exam trap
EC-Council often tests the distinction between acquisition tools (FTK Imager), analysis tools for specific artifacts (Volatility for memory, Wireshark for network), and comprehensive timeline tools (Plaso), so the trap here is assuming a general-purpose tool like FTK Imager can perform artifact parsing and timeline creation when it is only for imaging and preview.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Plaso (log2timeline)
Plaso (log2timeline) is the correct tool because it is specifically designed to create super timelines of file system activity from disk images. It parses a wide range of artifacts including the Windows Registry, Prefetch files, event logs, and other log files, correlating timestamps to reconstruct a chronological sequence of system events.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Wireshark
Why it's wrong here
Wireshark is a network protocol analyzer that captures and inspects packets traversing a network interface, focusing on traffic like TCP/IP, HTTP, and DNS. It does not parse any file system metadata, logs, or disk artifacts, and it cannot reconstruct a temporal sequence of file system events. Therefore, it is entirely unsuitable for creating a file system timeline, as its entire data source is live network traffic, not storage media.
- ✗
Volatility
Why it's wrong here
Volatility is a memory forensics framework designed to analyze volatile memory (RAM) dumps, extracting artifacts such as running processes, kernel objects, network connections, and user credentials. It operates on memory captures, not on a raw disk image or live file system, and it lacks the parsers needed to interpret NTFS or ext4 metadata. Since the question requires a file system timeline, Volatility is inapplicable because it targets a different forensic artifact class (memory) rather than on-disk data.
- ✓
Plaso (log2timeline)
Why this is correct
Plaso, also known as log2timeline, is the correct tool because it is purpose-built for constructing super timelines from diverse forensic artifacts, including file system metadata, event logs, and application logs. It ingests disk images or directories, parses time-stamped evidence using modular parsers, and outputs a unified, correlated timeline in SQLite or bodyfile format. Unlike single-purpose tools, Plaso correlates timestamps from multiple sources, enabling robust reconstruction of file system activity such as creation, modification, and access events.
- ✗
FTK Imager
Why it's wrong here
FTK Imager is a forensic imaging and evidence acquisition tool used to create sector-level duplicate images (e.g., E01, RAW) and to view or mount images for basic inspection. It does not provide any timeline generation capability; its primary functions are acquisition, hashing, and mount access to evidence files. While it can show file metadata in a browsing interface, it cannot recursively parse and correlate forensic artifacts into a chronological timeline, so it is the wrong choice for this specific task.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.