RA10 • Unit 1 • Mark Scheme 3
Zoom 100% 1 / 1 Question Paper
Mark Schemes
BTEC Level 3 National Extended Certificate in IT
Mark Scheme — Predicted Paper 3
Unit 1: Information Technology Systems
BTEC Level 3 National Extended Certificate in Information Technology
Paper ReferenceRA10/IT/U1/PP3
Total marks90
SeriesPractice Paper — January 2027

This mark scheme has been prepared by RA10 for use with Predicted Paper 3. It follows the Pearson BTEC Level 3 mark scheme conventions for Unit 1 (AAQ 2025, Issue 5).

Using this mark scheme:
For short-answer questions, award the marks specified. "Accept any other appropriate/alternative response" means equivalent correct answers should be credited.
For levels-based questions, use the Level Descriptors holistically alongside the indicative content. Indicative content is not a checklist.

For revision purposes only. Not an official Pearson qualification document.

Question 1 — Threats & Protection   (22 marks total)

(a)(i)Give two external threats to the clinic's data.2 marks
Award one mark for each correct external threat, up to a maximum of two marks.
  • Viruses/malware (1)
  • Hackers/unauthorised access (1)
  • Social engineering/phishing (1)
  • Natural disaster (1)
  • Denial-of-service attack (1)
Accept any other appropriate external threat
(a)(ii)Give two output devices that will be needed.2 marks
Award one mark for each correct output device, up to a maximum of two marks.
  • Monitor/screen (1)
  • Printer (1)
  • Speakers (1)
  • Projector (1)
Accept any other appropriate output device
(b)(i)Explain two benefits of using antivirus software.4 marks
Award one mark for identification and one mark for a linked justification/expansion, up to a maximum of four marks.
  • Detects malware (1) by scanning files for known threats (1)
  • Removes/quarantines infected files (1) preventing damage or spread (1)
  • Real-time protection (1) monitors the system continuously (1)
  • Regular updates (1) keep it effective against new viruses (1)
Accept any other appropriate/alternative response
(b)(ii)Explain two drawbacks of a breach of patient data for the clinic.4 marks
Award one mark for identification and one mark for a linked justification/expansion, up to a maximum of four marks.
  • Financial loss (1) — fines or compensation following a breach (1)
  • Reputational damage (1) — patients lose trust in the clinic (1)
  • Legal action (1) — breach of data protection law risks penalties (1)
  • Operational disruption (1) — staff cannot access records to treat patients (1)
Accept any other appropriate impact
(c)Describe how a firewall protects the data stored on the system.4 marks
Award one mark per correct linked point, up to a maximum of four marks.
  • A firewall examines/checks data packets entering and leaving the network (1)
  • It filters traffic against a set of security rules (1)
  • It blocks unauthorised/unsolicited external access to the system (1)
  • So malicious traffic cannot reach (and harm) the stored data (1)
Accept any other appropriate/alternative response
(d)Discuss techniques to protect patient data, including encryption.6 marks — Levels
Indicative Content (not prescriptive — reward any well-developed point)
  • Encryption — data is scrambled so it cannot be read if intercepted
  • Multi-factor authentication / 2FA — a second factor blocks access if a password is stolen
  • Biometric authentication — unique physical feature restricts logins to authorised staff
  • Firewalls — block unauthorised network traffic
  • Access control/permissions — restrict data access to authorised staff
LevelMarkDescriptor
00No rewardable material.
11–3Identifies one technique with limited explanation of how it protects data. (AO2)
24–5Identifies two or more techniques with developed explanation of how each protects patient data. (AO2/AO3a)
36Thoroughly discusses several techniques (e.g. encryption, MFA, biometrics, firewalls) with clear explanation of how each protects data, contextualised. (AO2/AO3a)
Question 1 Total: 22 marks

Question 2 — Backup & Software   (23 marks total)

(a)Give two types of application software used by the firm.2 marks
Award one mark for each correct type of application software, up to a maximum of two marks.
  • Word processing software (1)
  • Spreadsheet software (1)
  • Database software (1)
  • Presentation software (1)
  • Email client (1)
  • Accounting/business software (1)
  • Web browser (1)
Accept any other appropriate application software type
(b)(i)Explain two benefits of regularly backing up client data.4 marks
Award one mark for identification and one mark for a linked justification/expansion, up to a maximum of four marks.
  • Protects against data loss (1) — data can be restored if lost or corrupted (1)
  • Quick recovery (1) — minimises downtime after an incident (1)
  • Off-site copies (1) — survive physical damage to the building (1)
  • Version history (1) — earlier versions can be recovered (1)
Accept any other appropriate/alternative response
(b)(ii)Explain two benefits of encrypting client data.4 marks
Award one mark for identification and one mark for a linked justification/expansion, up to a maximum of four marks.
  • Scrambles data (1) so it is unreadable without the key (1)
  • Protects data at rest (1) — stored data is secure if a device is stolen (1)
  • Protects data in transit (1) — intercepted traffic cannot be read (1)
  • Builds customer trust (1) — sensitive data is kept confidential (1)
Accept any other appropriate/alternative response
(c)Explain two acceptable behaviours that should be included in the Acceptable Use Policy.4 marks
Award one mark for identification and one mark for a linked justification/expansion, up to a maximum of four marks.
  • Do not visit inappropriate/offensive websites (1) — avoids malware and misuse of company systems (1)
  • Do not download unauthorised software (1) — prevents malware and licence breaches (1)
  • Do not share passwords (1) — protects accounts from unauthorised access (1)
  • Use systems only for authorised work purposes (1) — protects productivity and data (1)
Accept any other appropriate acceptable behaviour
(d)Evaluate the features of utility software that can be used to maintain, manage and optimise the computer systems.9 marks — Levels
Indicative Content (not prescriptive — reward any well-developed point)
  • Antivirus software — detects/quarantines/removes malware
  • Disk defragmentation — reorganises files to improve access speed
  • Disk cleanup — removes temporary/unwanted files to free storage
  • Backup software — schedules automatic backups to protect against data loss
  • Compression software — reduces file size to save storage space
  • System monitoring/performance tools — identify bottlenecks and resource usage
  • Encryption tools — secure sensitive data
  • Firewall management — controls network traffic
  • Cost vs benefit — most utility software is low cost; some require licences
  • Needs staff knowledge to use effectively — training requirement
LevelMarkDescriptor
00No rewardable material.
11–3Basic understanding of utility software. Names one or two utilities with limited explanation of their role. (AO2)
24–6Good understanding. Describes several utility software features and explains how they maintain, manage or optimise the system in context. (AO2/AO3a)
37–9Comprehensive evaluation. Discusses a range of utility software with clear evaluation of how each maintains/manages/optimises, weighing benefits against considerations such as cost and training, with a justified view. (AO2/AO3a/AO3b)
Question 2 Total: 23 marks

Question 3 — Remote & Legal   (21 marks total)

(a)Draw a diagram to show how the network is set up and how Ravi connects when working remotely. The diagram must include devices and systems that are used, connection types and annotations.6 marks
Award up to six marks for a correct annotated diagram.
  • Central server shown (1)
  • Desktop computers shown connecting to the server (1)
  • Printer (and managers' offices) shown (1)
  • The mobile worker's laptop and smartphone shown (1)
  • PAN between laptop and smartphone shown (1)
  • Connection over the internet to the office server shown with annotations (1)
(b)Explain one factor that affects the choice of connection type.2 marks
Award one mark for identification and one mark for a linked justification/expansion, up to a maximum of two marks.
  • Performance/speed (1) — the connection must be fast enough for the work (1)
  • Cost (1) — wired vs wireless and setup costs must suit the budget (1)
  • Mobility (1) — wireless suits staff who move around (1)
  • Reliability (1) — wired connections are usually more stable (1)
  • Security (1) — wired is harder to intercept than wireless (1)
Accept any other appropriate factor
(c)Explain two other impacts of the loss of the firm's client data.4 marks
Award one mark for identification and one mark for a linked justification/expansion, up to a maximum of four marks.
  • Financial loss (1) — lost records may mean lost business/income or compensation (1)
  • Reputational damage (1) — clients lose trust in the organisation (1)
  • Legal/compliance breach (1) — may breach data protection legislation, risking fines (1)
  • Operational disruption (1) — staff cannot do their work without the lost data (1)
Accept any other appropriate impact. Do not accept 'loss of data' (given in the question).
(d)Evaluate the legal and ethical issues when the firm transfers client drawings and data between sites.9 marks — Levels
Indicative Content (not prescriptive — reward any well-developed point)
  • Must comply with UK GDPR / Data Protection Act
  • Lawful basis for processing and client consent
  • Data kept secure, accurate and up to date
  • Client rights: access, rectification, erasure, portability
  • Computer Misuse Act — protection against unauthorised access
  • Consequences of breach — fines, legal action, reputational damage
  • Staff training and clear data policies
LevelMarkDescriptor
00No rewardable material.
11–3Basic understanding. Names legislation with limited application to the organisation's data. (AO2)
24–6Good application. Discusses several legal requirements and how they apply to client data with some development. (AO2/AO3a)
37–9Comprehensive evaluation. Thorough discussion of legal obligations (GDPR, Computer Misuse Act), client rights and consequences of breach, with a balanced judgement. (AO2/AO3a/AO3b)
Question 3 Total: 21 marks

Question 4 — Cloud & Servers   (24 marks total)

(a)Describe how the company can use one cloud computing model.3 marks
Award up to three marks for an accurate description of how the organisation can use a cloud computing model.
  • Identifies a model (e.g. IaaS/SaaS/PaaS or cloud backup service) (1)
  • Describes how data is stored on remote servers managed by a provider (1)
  • Explains access over the internet rather than on-site hardware (1)
Accept any appropriate cloud model correctly described
(b)Evaluate how different cloud computing models could fit the needs of the company.9 marks — Levels
Indicative Content (not prescriptive — reward any well-developed point)
  • Infrastructure as a Service (IaaS) — rental of servers/storage; most control, most management
  • Platform as a Service (PaaS) — development platform; middle level of control
  • Software as a Service (SaaS) — ready-made application; least control, least management
  • Private cloud — dedicated to one organisation; more secure, more costly
  • Public cloud — shared provider; cheaper, less control
  • Hybrid cloud — mixes private and public; balances security and cost
  • For backup: public cloud/IaaS is cost-effective for large data volumes
  • Security/compliance considerations for the specific organisation
  • Scalability — cloud scales up/down with demand
  • Cost — pay-as-you-go vs capital expenditure
LevelMarkDescriptor
00No rewardable material.
11–3Basic understanding of cloud models. Names one or two models (IaaS/PaaS/SaaS or public/private) with limited application. (AO2)
24–6Good evaluation. Compares several cloud models and how they could meet the organisation's needs, with some development. (AO2/AO3a)
37–9Comprehensive evaluation. Thorough comparison of multiple cloud models (service and deployment), evaluated against the organisation's needs, security, cost and scalability, with a justified recommendation. (AO2/AO3a/AO3b)
(c)Evaluate the performance and efficiency of a web server compared to a file server.12 marks — Levels
Indicative Content (not prescriptive — reward any well-developed point)
  • Web server — serves web pages over the internet; enables public access
  • File server — stores and shares files on a local network; controlled centrally
  • Performance: web server optimised for concurrent HTTP requests; file server for file I/O throughput
  • Efficiency: web server caches content and handles many simultaneous clients; file server provides centralised storage
  • Security: web server exposed to the internet (needs strong protection); file server on the internal network is more contained
  • Accessibility: web server accessible remotely; file server typically LAN/remote access only
  • Suitability depends on need — serving content publicly vs internal file sharing
  • Cost and management considerations of each
LevelMarkDescriptor
00No rewardable material.
11–4Basic understanding of web server and/or file server. Limited comparison, mostly descriptive. (AO2)
25–8Good evaluation comparing performance and efficiency of web server vs file server with several points developed in context. (AO2/AO3a)
39–12Comprehensive evaluation. Thorough, balanced comparison covering performance, efficiency, security, accessibility and suitability, clearly contextualised, with a justified conclusion. (AO2/AO3a/AO3b)
Question 4 Total: 24 marks     Paper Total: 90 marks