CHFI OS and Network Forensics Practice Question
Which tool is commonly used for timeline analysis in digital forensics, allowing examiners to parse and correlate timestamps from various artifacts?
⚠ Common exam trap
EC-Council CHFI often tests the distinction between file system analysis tools (Sleuth Kit) and timeline correlation tools (log2timeline), so candidates may mistakenly choose Sleuth Kit because it includes mactime, forgetting that log2timeline is the primary tool for building a super-timeline from multiple artifacts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
log2timeline
log2timeline (now part of the Plaso framework) is the de facto tool for timeline analysis in digital forensics. It parses a wide range of artifacts (e.g., $MFT, $UsnJrnl, Prefetch, Registry hives, event logs) and correlates their timestamps into a unified, super-timeline, enabling examiners to reconstruct system activity chronologically.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
log2timeline
Why this is correct
log2timeline/Plaso is the forensic tool for creating timelines from multiple artifacts.
- ✗
Sleuth Kit
Why it's wrong here
Sleuth Kit is for file system analysis, not timeline parsing.
- ✗
Nmap
Why it's wrong here
Nmap is a network scanner, not a forensic timeline tool.
- ✗
Wireshark
Why it's wrong here
Wireshark is for packet capture analysis, not timeline creation.
Go deeper
Related to this question
Learn chapter
Overview of Computer Forensics and Investigation Process
Key term
Memory Acquisition
Memory acquisition is the process of capturing the contents of a computer's volatile memory to preserve data for forensic analysis and incident response.
Key term
Evidence Admissibility
Evidence admissibility is the legal and technical standard that determines whether digital evidence can be used in a court of law.
About these practice questions
This CHFI question is part of Courseiva's 205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.