CHFI OS and Network Forensics Practice Question
Which tool is commonly used for timeline analysis in digital forensics, combining multiple artifacts into a super timeline?
⚠ Common exam trap
EC-Council often tests the distinction between a tool that performs a specific function (Plaso for super timeline creation) versus a platform that integrates multiple tools (Autopsy), leading candidates to mistakenly choose Autopsy because it is a more familiar, all-in-one forensic suite.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Plaso
Plaso (log2timeline) is the correct tool for timeline analysis because it ingests multiple forensic artifacts (e.g., registry hives, event logs, file system metadata, browser history) and correlates them into a single, unified super timeline. This allows investigators to reconstruct events across different data sources in chronological order, which is essential for timeline analysis in digital forensics.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Plaso
Why this is correct
Plaso (formerly log2timeline) is the de facto standard for creating comprehensive 'super timelines' in digital forensics. It recursively parses file system metadata, system logs, browser history, registry hives, and numerous application artifacts, normalizing timestamps to UTC and exporting them into a unified SQLite or CSV timeline. This aggregated, holistic view of system activity is what makes Plaso the benchmark tool for timeline analysis.
- ✗
Autopsy
Why it's wrong here
Autopsy is a graphical front-end for The Sleuth Kit, providing an intuitive user interface for examining disk images, recovering files, and viewing file system metadata. While it includes a 'Timeline' viewer feature, the actual artifact-based timeline extraction is delegated to Plaso via an ingest module; Autopsy itself does not perform the deep artifact parsing required for comprehensive timeline analysis.
- ✗
Sleuth Kit
Why it's wrong here
The Sleuth Kit (TSK) is a collection of command-line tools (e.g., fls, mmls, icat) focused on recovering and analyzing file system structures at a low level. Although TSK includes mactime, which can generate a timeline from body files, that output is limited to file system timestamps and file activity, not the application-level artifacts (OS logs, browser data, USB history) that Plaso is designed to correlate. Thus, TSK alone is insufficient for full timeline analysis.
- ✗
Wireshark
Why it's wrong here
Wireshark is a network protocol analyzer used for capturing and inspecting packets on a network interface. It has no capability to parse file system metadata, application artifacts, or system logs on a forensic image, so it is completely unrelated to timeline analysis in a host-based digital forensics context.
Go deeper
Related to this question
Learn chapter
Database Forensics: Investigating Data Breaches
Key term
Forensic Evidence Collection
Forensic evidence collection is the process of identifying, preserving, and gathering digital data from computers and devices in a way that keeps it valid for use in legal investigations or internal incident response.
Key term
Memory Acquisition
Memory acquisition is the process of capturing the contents of a computer's volatile memory to preserve data for forensic analysis and incident response.
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.