Courseiva
OS and Network Forensics →hardMultiple Choice

CHFI OS and Network Forensics Practice Question

A forensic tool outputs a timeline of file system events. The analyst needs to correlate registry modifications with file creation times. Which tool is specifically designed for super timeline creation from multiple sources?

⚠ Common exam trap

EC-Council often tests the distinction between tools that perform low-level file system analysis (Sleuth Kit) and those that aggregate multiple artifact sources into a unified timeline (Plaso), leading candidates to confuse Sleuth Kit's 'fls' output with a super timeline.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Plaso

Plaso (log2timeline) is specifically designed to create super timelines by aggregating and correlating events from multiple sources, including file system metadata, registry hives, and event logs. It parses artifacts like NTFS $MFT, USN journal, and registry keys (e.g., NTUSER.DAT) to produce a unified timeline, enabling the analyst to correlate registry modifications with file creation times.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Plaso

    Why this is correct

    Plaso (formerly log2timeline) is an open-source Python framework purpose-built for super timeline generation. It parses dozens of artifact types—file system metadata (MACB timestamps), log files, registry hives, browser history, and more—and outputs unified timelines in formats like SQLite, CSV, or Elasticsearch. It is the tool most directly associated with 'outputs a timeline of file system events' because it aggregates evidence from multiple sources into a single chronological narrative.

  • ✗

    Autopsy

    Why it's wrong here

    Autopsy is a GUI forensic platform built on The Sleuth Kit, offering modules for disk imaging, keyword search, hash analysis, and file viewing. It can visualize file system timelines using bodyfile-style data, but it is primarily a consumer and presenter of timelines rather than the engine that creates them from multiple artifact sources. Its core strength is interactive investigation, not automated multi-source artifact parsing, so for the stated purpose of a tool that outputs comprehensive file-system-event timelines, Autopsy is not the best answer.

  • ✗

    Volatility

    Why it's wrong here

    Volatility is a memory forensics framework focused on acquiring and analyzing RAM dumps. It extracts running processes, network connections, loaded drivers, and kernel objects from volatile memory images, and while it has a 'timeliner' plugin, that timeline reflects memory artifacts rather than file system events on disk. Because it operates on memory images instead of disk images or distributed logs, it cannot produce the file-system timeline described in the question.

  • ✗

    Sleuth Kit

    Why it's wrong here

    The Sleuth Kit (TSK) is a low-level C++/Python library and command-line tool collection for disk image dissection, including fls, istat, and mactime. Its mactime tool can generate a bodyfile-based file system timeline, but timeline generation is only one component of a broader toolkit, requiring the analyst to assemble body files first. Unlike Plaso, TSK does not parse multiple heterogeneous sources such as logs and registry hives into a super timeline, so it is not the correct answer to the question.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.