Courseiva
OS and Network Forensics →mediumMultiple Choice

CHFI OS and Network Forensics Practice Question

Which tool is commonly used for timeline analysis in digital forensics, allowing examiners to parse and correlate timestamps from various artifacts?

⚠ Common exam trap

EC-Council CHFI often tests the distinction between file system analysis tools (Sleuth Kit) and timeline correlation tools (log2timeline), so candidates may mistakenly choose Sleuth Kit because it includes mactime, forgetting that log2timeline is the primary tool for building a super-timeline from multiple artifacts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

log2timeline

log2timeline (now part of the Plaso framework) is the de facto tool for timeline analysis in digital forensics. It parses a wide range of artifacts (e.g., $MFT, $UsnJrnl, Prefetch, Registry hives, event logs) and correlates their timestamps into a unified, super-timeline, enabling examiners to reconstruct system activity chronologically.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    log2timeline

    Why this is correct

    log2timeline parses timestamps from disparate artefacts and normalises them into a single super-timeline, letting examiners correlate activity across file system, registry and log sources. This satisfies the requirement to parse and correlate timestamps from various artefacts.

  • ✗

    Sleuth Kit

    Why it's wrong here

    Sleuth Kit recovers and analyses filesystem data, including deleted inodes and file metadata, but its timeline generation depends on external mactime processing and it does not natively correlate disparate artefact sources. The stem requires parsing and correlating timestamps from various artefacts. Sleuth Kit is correct for filesystem-level forensic examination and recovery.

  • ✗

    Nmap

    Why it's wrong here

    Nmap performs network host discovery, port scanning and service fingerprinting; it produces no artefact timestamp correlation or super-timeline. The question requires parsing and correlating timestamps across forensic artefacts. Nmap is correct for mapping live hosts and open ports during the reconnaissance phase of an investigation.

  • ✗

    Wireshark

    Why it's wrong here

    Wireshark captures and dissects network packets, reconstructing protocol conversations rather than parsing filesystem, registry or log timestamps into a correlated timeline. The stem requires artefact timestamp correlation. Wireshark is correct when an examiner must analyse captured network traffic for exfiltration or command-and-control activity.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.