Courseiva
OS and Network Forensics →easyMultiple Choice

CHFI OS and Network Forensics Practice Question

Which tool is specifically designed for timeline analysis of forensic artifacts across multiple systems and can process output from various forensic tools?

⚠ Common exam trap

EC-Council often tests the distinction between a general forensic suite (like Autopsy or Sleuth Kit) and a specialized timeline analysis tool (log2timeline), leading candidates to choose a familiar tool that can perform some timeline functions but lacks the cross-tool aggregation capability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

log2timeline

log2timeline (now part of the Plaso framework) is specifically designed for super timeline creation, aggregating and correlating timestamps from multiple forensic artifacts across different systems. It can ingest output from tools like The Sleuth Kit, Autopsy, and others to produce a unified, high-resolution timeline for analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Autopsy

    Why it's wrong here

    Autopsy is a full-featured digital forensics GUI platform that wraps The Sleuth Kit and other modules, offering a timeline viewer as just one optional feature alongside file browsing, keyword search, and EXIF analysis. Its timeline capability, while functional, is an integrated plugin rather than the application's singular design goal. Because Autopsy serves primarily as an all-in-one case-management and analysis environment, it is not the dedicated tool for timeline analysis in the way log2timeline is.

  • ✗

    Wireshark

    Why it's wrong here

    Wireshark is a network protocol analyzer that captures live traffic and reads pcap files, dissecting packets to inspect headers and payloads at multiple protocol layers. Even though it records time-stamped frames and can show the sequence of network communications, its focus is entirely on network-level traffic, not on host-based forensic artifacts like file system metadata, registry keys, or application logs. Therefore Wireshark is fundamentally unrelated to the artifact timeline generation and correlation that the questioned capability requires.

  • ✗

    Sleuth Kit

    Why it's wrong here

    The Sleuth Kit (TSK) is a collection of low-level command-line utilities for examining file system and volume structure, such as fls for listing files, icat for extracting content, and mmls for partition layout. It does include the utility 'mactime' to convert body files into a basic timeline, but mactime is only a small ancillary component; TSK's primary focus is raw file-system and volume analysis, not ingesting dozens of log formats or registry data. Thus TSK is more of a building block for constructing timelines rather than a purpose-built timeline analysis tool like log2timeline.

  • ✓

    log2timeline

    Why this is correct

    log2timeline, now part of the Plaso project, is specifically engineered to acquire and analyze timestamps from a wide array of artifact sources—file system metadata, Windows Registry, event logs, browser history, and third-party application logs—into a unified SQLite timeline database. Its dedicated tools such as pinfo and psort filter, sort, and output event timelines, making it the canonical purpose-built solution for timestamp correlation in digital forensics. Unlike generic analysis platforms or packet analyzers, its entire architecture is centered on timeline generation and analysis.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.