Courseiva
OS and Network Forensics →mediumMultiple Select

CHFI OS and Network Forensics Practice Question

Which TWO of the following tools are primarily used for timeline analysis in digital forensics? (Select TWO.)

⚠ Common exam trap

EC-Council often tests the distinction between tools that are 'used in forensics' versus those 'primarily for timeline analysis,' so candidates may mistakenly select Autopsy because it is a popular forensics suite, but it is not a dedicated timeline analysis tool like mactime or Plaso.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Sleuth Kit (mactime)

The Sleuth Kit's mactime tool (option B) is correct because it builds a bodyfile of MAC times (modified, accessed, changed, and created timestamps) from file system metadata and renders it into a chronological timeline, which is the core of timeline analysis in digital forensics. Plaso (option D) is also correct because it is a Python-based engine that parses many artifact types and, via its log2timeline/psort components, produces a super-timeline correlating events across sources, making it a primary timeline analysis tool. Autopsy (option C) is a full forensic platform that can display timelines, but it is not primarily a timeline analysis tool in the sense of the dedicated mactime and Plaso utilities. Nmap (option A) is a network discovery and port-scanning tool, and Wireshark (option E) is a packet capture and protocol analyzer; neither is designed for building forensic event timelines.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Nmap

    Why it's wrong here

    Nmap is a network discovery and security auditing utility that probes hosts and services by sending crafted packets and analyzing responses. Its purpose is port scanning, OS fingerprinting, and service enumeration over live networks, not the reconstruction of filesystem or OS activity from forensic images. Consequently, it cannot parse MACB times or correlate artifacts into a chronological timeline, making it irrelevant to time-based forensic analysis.

  • ✓

    The Sleuth Kit (mactime)

    Why this is correct

    The Sleuth Kit's mactime tool parses the body file format produced by fls and other TSK tools to generate chronological timelines from disk images. It specifically correlates MACB times (modification, access, change, birth) for filesystem objects, enabling investigators to reconstruct file activity across a timeline. As a focused command-line utility within a broader forensic toolkit, mactime is a primary and canonical tool for timeline analysis, which is why this option is correct.

  • ✗

    Autopsy

    Why it's wrong here

    Autopsy is a graphical front-end that wraps The Sleuth Kit and other modules into a full digital forensics platform, offering ingestion, keyword search, hash filtering, and visualization. While Autopsy can display timeline views and events, it is not primarily a timeline tool; its breadth and GUI-driven workflow serve case management and end-to-end analysis rather than dedicated time-series reconstruction. Therefore, it is incorrect as a primary answer despite its ability to show timelines.

  • ✓

    Plaso

    Why this is correct

    Plaso, originally log2timeline, is an advanced super timeline tool that ingests numerous artifact types (registry hives, event logs, filesystem metadata, browser history) and outputs a unified, sorted timeline. It supports pluggable parsers and multi-processing to aggregate temporal evidence from disparate sources into a comprehensive chronological narrative. As a purpose-built and widely adopted timeline generation engine, Plaso is a correct choice for time-based forensic examination.

  • ✗

    Wireshark

    Why it's wrong here

    Wireshark is a network protocol analyzer that captures and dissects packets in real time or from a pcap file, focusing on traffic streams, headers, and payloads. Its timestamps reflect packet arrival times on a network interface, not filesystem or OS-level artifact activity, and it lacks parsers for forensic disk image formats. Because timeline analysis in digital forensics concerns host-based artifact correlation rather than network packet sequencing, Wireshark is not used for creating forensic timelines.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.