CHFI OS and Network Forensics Practice Question
Which TWO of the following tools are primarily used for timeline analysis in digital forensics? (Select TWO.)
⚠ Common exam trap
EC-Council often tests the distinction between tools that are 'used in forensics' versus those 'primarily for timeline analysis,' so candidates may mistakenly select Autopsy because it is a popular forensics suite, but it is not a dedicated timeline analysis tool like mactime or Plaso.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Sleuth Kit (mactime)
The Sleuth Kit's mactime tool (option B) is correct because it builds a bodyfile of MAC times (modified, accessed, changed, and created timestamps) from file system metadata and renders it into a chronological timeline, which is the core of timeline analysis in digital forensics. Plaso (option D) is also correct because it is a Python-based engine that parses many artifact types and, via its log2timeline/psort components, produces a super-timeline correlating events across sources, making it a primary timeline analysis tool. Autopsy (option C) is a full forensic platform that can display timelines, but it is not primarily a timeline analysis tool in the sense of the dedicated mactime and Plaso utilities. Nmap (option A) is a network discovery and port-scanning tool, and Wireshark (option E) is a packet capture and protocol analyzer; neither is designed for building forensic event timelines.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Nmap
Why it's wrong here
Nmap is a network discovery and security auditing utility that probes hosts and services by sending crafted packets and analyzing responses. Its purpose is port scanning, OS fingerprinting, and service enumeration over live networks, not the reconstruction of filesystem or OS activity from forensic images. Consequently, it cannot parse MACB times or correlate artifacts into a chronological timeline, making it irrelevant to time-based forensic analysis.
- ✓
The Sleuth Kit (mactime)
Why this is correct
The Sleuth Kit's mactime tool parses the body file format produced by fls and other TSK tools to generate chronological timelines from disk images. It specifically correlates MACB times (modification, access, change, birth) for filesystem objects, enabling investigators to reconstruct file activity across a timeline. As a focused command-line utility within a broader forensic toolkit, mactime is a primary and canonical tool for timeline analysis, which is why this option is correct.
- ✗
Autopsy
Why it's wrong here
Autopsy is a graphical front-end that wraps The Sleuth Kit and other modules into a full digital forensics platform, offering ingestion, keyword search, hash filtering, and visualization. While Autopsy can display timeline views and events, it is not primarily a timeline tool; its breadth and GUI-driven workflow serve case management and end-to-end analysis rather than dedicated time-series reconstruction. Therefore, it is incorrect as a primary answer despite its ability to show timelines.
- ✓
Plaso
Why this is correct
Plaso, originally log2timeline, is an advanced super timeline tool that ingests numerous artifact types (registry hives, event logs, filesystem metadata, browser history) and outputs a unified, sorted timeline. It supports pluggable parsers and multi-processing to aggregate temporal evidence from disparate sources into a comprehensive chronological narrative. As a purpose-built and widely adopted timeline generation engine, Plaso is a correct choice for time-based forensic examination.
- ✗
Wireshark
Why it's wrong here
Wireshark is a network protocol analyzer that captures and dissects packets in real time or from a pcap file, focusing on traffic streams, headers, and payloads. Its timestamps reflect packet arrival times on a network interface, not filesystem or OS-level artifact activity, and it lacks parsers for forensic disk image formats. Because timeline analysis in digital forensics concerns host-based artifact correlation rather than network packet sequencing, Wireshark is not used for creating forensic timelines.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Forensic Investigation Process and Methodology
Key term
Evidence Admissibility
Evidence admissibility is the legal and technical standard that determines whether digital evidence can be used in a court of law.
Key term
FTK Imager
FTK Imager is a free forensic imaging tool used to create exact copies of computer drives and storage devices for digital evidence analysis.
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.