GCSE (9-1) Computer Science
Mark Scheme
J277/01: Unit 1.6 Computer Misuse Act
Question Answer Marks Guidance
1 Level 2: Unauthorised access with intent to commit (or facilitate) further offences (2).

(Award 1 mark if "intent to commit further offences" is partially described but incomplete, e.g., "Hacking to do something else").
2
Examiner Note: The key differentiator for Level 2 is the intent to do something more than just looking (e.g., fraud, theft).
2 Guessing a teacher's password to look at their grade book. 1
Examiner Note: "Storing data without encryption" is a Data Protection Act issue, not CMA.
3
  • It means the user does not have permission/consent (1).
  • From the owner/administrator of the system to access that specific program or data (1).
2
Crucial concept: If you have permission, it is not an offence under this Act.
4
  • (a) Level 1 (Unauthorised access to computer material).
  • (b) Level 3 (Unauthorised acts with intent to impair).
  • (c) Level 2 (Unauthorised access with intent to commit further offences).
3
1 mark per correct identification.
5a Computer Misuse Act (1990). 1
Accept CMA.
5b
  • The attack was intended to prevent the server from working correctly / crash the server (1).
  • This counts as "impairing the operation" of the computer (1).
2
Examiner Note: Students must link the "crash" to the legal wording "impairing operation" or "modification".
6
  • They only had permission for specific data (addresses), not all data (1).
  • Accessing the salary data was outside the scope of their permission, making that specific action unauthorised (1).
2
This tests the nuance that having a login doesn't mean you can look at everything.
7 Indicative Content:
Authorisation:
  • The Penetration Tester has explicit permission (a contract) from the company owner.
  • The CMA only applies to unauthorised access. Since the tester is authorised, no law is broken.
Intent:
  • The Tester's intent is to improve security (prevent impairment).
  • The Hacker's intent is to steal data (Level 2) or damage the system (Level 3).

Mark Band Criteria:
Level 3 (4–5 marks): Clear detailed comparison. Mentions permission/contract. Correctly uses "Unauthorised".
Level 2 (2–3 marks): Explains "good" vs "bad". Mentions permission but link to legislation is weaker.
Level 1 (1 mark): Basic statement (e.g., "The tester is hired").
5
Common Pitfall: Students often discuss "Ethical Hacking" generally without linking back to the "unauthorised" requirement of the Act.