CHFI OS and Network Forensics Practice Question
During a forensic investigation of a compromised Linux server, an analyst checks /var/log/auth.log and finds multiple entries like "Failed password for root from 10.0.0.5 port 22 ssh2". Which tool is BEST suited to analyze the timeline of these events?
⚠ Common exam trap
The EC-Council CHFI exam often tests the distinction between network analysis tools (Nmap, Wireshark) and forensic timeline tools (log2timeline), trapping candidates who confuse packet-level analysis with log-based event correlation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
log2timeline
C is correct because log2timeline (part of the Plaso framework) is specifically designed to parse multiple log sources, including /var/log/auth.log, and create a super timeline that correlates events by timestamp. This allows the analyst to reconstruct the exact sequence of failed SSH login attempts from 10.0.0.5, which is essential for timeline analysis in forensic investigations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Nmap
Why it's wrong here
Nmap actively probes hosts to enumerate open ports and services, generating new traffic rather than reading existing log entries; it produces no timeline from auth.log. It is tempting because it identifies SSH on port 22, but that suits reconnaissance or vulnerability scanning, not post-incident log timeline reconstruction.
- ✗
Wireshark
Why it's wrong here
Wireshark decodes captured network packets, so it cannot parse the textual auth.log entries or order their timestamps; the SSH failures were logged after the packets were reassembled. It is tempting because it would reveal the brute-force traffic on port 22, but only if packet capture existed and the question asked about network-level evidence.
- ✓
log2timeline
Why this is correct
log2timeline parses diverse log and artefact sources into a unified chronological bodyfile, letting the analyst correlate the repeated SSH authentication failures from 10.0.0.5 against other system events. This satisfies the requirement to analyse event timeline ordering, not merely read entries.
- ✗
Autopsy
Why it's wrong here
Autopsy parses disk images and file system artefacts, so it would only reach auth.log after ingesting a forensic image, and its timeline view is built from file system metadata rather than syslog event ordering. It is tempting as a general forensic suite, but it suits dead-box disk analysis, not direct text log correlation.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.