CHFI OS and Network Forensics Practice Question
Which tool is specifically designed for timeline analysis in digital forensics and is the command-line version of the log2timeline framework?
⚠ Common exam trap
EC-Council often tests the distinction between the original Perl-based log2timeline and the Python-based Plaso rewrite, as well as the difference between command-line tools (like Plaso) and GUI tools (like Autopsy, which is based on The Sleuth Kit, not log2timeline).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Plaso
Plaso (Python Log2Timeline) is the command-line version of the log2timeline framework, specifically engineered for super timeline creation and timeline analysis in digital forensics. It parses multiple log and artifact sources (e.g., Windows Event Logs, Prefetch, Registry hives) into a unified, high-performance timeline database (SQLite or Elasticsearch), enabling examiners to correlate events across time. This makes it the direct answer to a question asking for the CLI tool derived from the log2timeline framework.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Autopsy
Why it's wrong here
Autopsy is a graphical digital forensics platform that provides a broad range of investigative features, including a timeline visualization tab. However, that timeline capability is not native; it relies on the Plaso/log2timeline engine and body files to generate the chronological view. As a GUI front-end, Autopsy is not specifically built for timeline analysis, but rather for comprehensive forensic examination.
- ✗
Sleuth Kit
Why it's wrong here
The Sleuth Kit is a library and collection of low-level command-line utilities (e.g., fls, icat, mmls) designed for analyzing disk images and file system structures. While it includes tools like mactime that can process body files to produce timelines, it is not a dedicated timeline analysis tool itself. Its primary purpose is file system forensic extraction and recovery, not the creation of super timelines from diverse artifacts.
- ✓
Plaso
Why this is correct
Plaso, also known as log2timeline, is the command-line tool specifically engineered for timeline analysis. It recursively parses numerous artifact types—such as file system metadata, registry hives, and application logs—to create comprehensive 'super timelines' with unified timestamps. Plaso aggregates and normalizes timestamps into a single, queryable event database (often SQLite or Elasticsearch), making it the de facto standard for advanced timeline construction in forensic investigations.
- ✗
Wireshark
Why it's wrong here
Wireshark is a network protocol analyzer that captures live traffic and dissects packet headers and payloads for communication diagnostics. Its core function is inspecting network data streams, not reconstructing file system or system activity timelines. Timelines in digital forensics concern event chronology from artifacts like files and logs, which is entirely outside Wireshark's intended purpose, as it focuses on packet-level network analysis.
Go deeper
Related to this question
Learn chapter
Legal and Ethical Issues in Digital Forensics
Key term
Memory Acquisition
Memory acquisition is the process of capturing the contents of a computer's volatile memory to preserve data for forensic analysis and incident response.
Key term
Evidence Admissibility
Evidence admissibility is the legal and technical standard that determines whether digital evidence can be used in a court of law.
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.