RA10
Mark Schemes
BTEC Level 3 National Extended Certificate in IT
Mark Scheme — Predicted Paper 3
Unit 1: Information Technology Systems
BTEC Level 3 National Extended Certificate in Information Technology
| Paper Reference | RA10/IT/U1/PP3 |
| Total marks | 90 |
| Series | Practice Paper — January 2027 |
This mark scheme has been prepared by RA10 for use with Predicted Paper 3. It follows the Pearson BTEC Level 3 mark scheme conventions for Unit 1 (AAQ 2025, Issue 5).
Using this mark scheme:
For short-answer questions, award the marks specified. "Accept any other appropriate/alternative response" means equivalent correct answers should be credited.
For levels-based questions, use the Level Descriptors holistically alongside the indicative content. Indicative content is not a checklist.
For revision purposes only. Not an official Pearson qualification document.
Question 1 — Threats & Protection (22 marks total)
Award one mark for each correct external threat, up to a maximum of two marks.
- Viruses/malware (1)
- Hackers/unauthorised access (1)
- Social engineering/phishing (1)
- Natural disaster (1)
- Denial-of-service attack (1)
Accept any other appropriate external threat
Award one mark for each correct output device, up to a maximum of two marks.
- Monitor/screen (1)
- Printer (1)
- Speakers (1)
- Projector (1)
Accept any other appropriate output device
Award one mark for identification and one mark for a linked justification/expansion, up to a maximum of four marks.
- Detects malware (1) by scanning files for known threats (1)
- Removes/quarantines infected files (1) preventing damage or spread (1)
- Real-time protection (1) monitors the system continuously (1)
- Regular updates (1) keep it effective against new viruses (1)
Accept any other appropriate/alternative response
Award one mark for identification and one mark for a linked justification/expansion, up to a maximum of four marks.
- Financial loss (1) — fines or compensation following a breach (1)
- Reputational damage (1) — patients lose trust in the clinic (1)
- Legal action (1) — breach of data protection law risks penalties (1)
- Operational disruption (1) — staff cannot access records to treat patients (1)
Accept any other appropriate impact
Award one mark per correct linked point, up to a maximum of four marks.
- A firewall examines/checks data packets entering and leaving the network (1)
- It filters traffic against a set of security rules (1)
- It blocks unauthorised/unsolicited external access to the system (1)
- So malicious traffic cannot reach (and harm) the stored data (1)
Accept any other appropriate/alternative response
Indicative Content (not prescriptive — reward any well-developed point)
- Encryption — data is scrambled so it cannot be read if intercepted
- Multi-factor authentication / 2FA — a second factor blocks access if a password is stolen
- Biometric authentication — unique physical feature restricts logins to authorised staff
- Firewalls — block unauthorised network traffic
- Access control/permissions — restrict data access to authorised staff
| Level | Mark | Descriptor |
| 0 | 0 | No rewardable material. |
| 1 | 1–3 | Identifies one technique with limited explanation of how it protects data. (AO2) |
| 2 | 4–5 | Identifies two or more techniques with developed explanation of how each protects patient data. (AO2/AO3a) |
| 3 | 6 | Thoroughly discusses several techniques (e.g. encryption, MFA, biometrics, firewalls) with clear explanation of how each protects data, contextualised. (AO2/AO3a) |
Question 1 Total: 22 marks
Question 2 — Backup & Software (23 marks total)
Award one mark for each correct type of application software, up to a maximum of two marks.
- Word processing software (1)
- Spreadsheet software (1)
- Database software (1)
- Presentation software (1)
- Email client (1)
- Accounting/business software (1)
- Web browser (1)
Accept any other appropriate application software type
Award one mark for identification and one mark for a linked justification/expansion, up to a maximum of four marks.
- Protects against data loss (1) — data can be restored if lost or corrupted (1)
- Quick recovery (1) — minimises downtime after an incident (1)
- Off-site copies (1) — survive physical damage to the building (1)
- Version history (1) — earlier versions can be recovered (1)
Accept any other appropriate/alternative response
Award one mark for identification and one mark for a linked justification/expansion, up to a maximum of four marks.
- Scrambles data (1) so it is unreadable without the key (1)
- Protects data at rest (1) — stored data is secure if a device is stolen (1)
- Protects data in transit (1) — intercepted traffic cannot be read (1)
- Builds customer trust (1) — sensitive data is kept confidential (1)
Accept any other appropriate/alternative response
Award one mark for identification and one mark for a linked justification/expansion, up to a maximum of four marks.
- Do not visit inappropriate/offensive websites (1) — avoids malware and misuse of company systems (1)
- Do not download unauthorised software (1) — prevents malware and licence breaches (1)
- Do not share passwords (1) — protects accounts from unauthorised access (1)
- Use systems only for authorised work purposes (1) — protects productivity and data (1)
Accept any other appropriate acceptable behaviour
Indicative Content (not prescriptive — reward any well-developed point)
- Antivirus software — detects/quarantines/removes malware
- Disk defragmentation — reorganises files to improve access speed
- Disk cleanup — removes temporary/unwanted files to free storage
- Backup software — schedules automatic backups to protect against data loss
- Compression software — reduces file size to save storage space
- System monitoring/performance tools — identify bottlenecks and resource usage
- Encryption tools — secure sensitive data
- Firewall management — controls network traffic
- Cost vs benefit — most utility software is low cost; some require licences
- Needs staff knowledge to use effectively — training requirement
| Level | Mark | Descriptor |
| 0 | 0 | No rewardable material. |
| 1 | 1–3 | Basic understanding of utility software. Names one or two utilities with limited explanation of their role. (AO2) |
| 2 | 4–6 | Good understanding. Describes several utility software features and explains how they maintain, manage or optimise the system in context. (AO2/AO3a) |
| 3 | 7–9 | Comprehensive evaluation. Discusses a range of utility software with clear evaluation of how each maintains/manages/optimises, weighing benefits against considerations such as cost and training, with a justified view. (AO2/AO3a/AO3b) |
Question 2 Total: 23 marks
Question 3 — Remote & Legal (21 marks total)
Award up to six marks for a correct annotated diagram.
- Central server shown (1)
- Desktop computers shown connecting to the server (1)
- Printer (and managers' offices) shown (1)
- The mobile worker's laptop and smartphone shown (1)
- PAN between laptop and smartphone shown (1)
- Connection over the internet to the office server shown with annotations (1)
Award one mark for identification and one mark for a linked justification/expansion, up to a maximum of two marks.
- Performance/speed (1) — the connection must be fast enough for the work (1)
- Cost (1) — wired vs wireless and setup costs must suit the budget (1)
- Mobility (1) — wireless suits staff who move around (1)
- Reliability (1) — wired connections are usually more stable (1)
- Security (1) — wired is harder to intercept than wireless (1)
Accept any other appropriate factor
Award one mark for identification and one mark for a linked justification/expansion, up to a maximum of four marks.
- Financial loss (1) — lost records may mean lost business/income or compensation (1)
- Reputational damage (1) — clients lose trust in the organisation (1)
- Legal/compliance breach (1) — may breach data protection legislation, risking fines (1)
- Operational disruption (1) — staff cannot do their work without the lost data (1)
Accept any other appropriate impact. Do not accept 'loss of data' (given in the question).
Indicative Content (not prescriptive — reward any well-developed point)
- Must comply with UK GDPR / Data Protection Act
- Lawful basis for processing and client consent
- Data kept secure, accurate and up to date
- Client rights: access, rectification, erasure, portability
- Computer Misuse Act — protection against unauthorised access
- Consequences of breach — fines, legal action, reputational damage
- Staff training and clear data policies
| Level | Mark | Descriptor |
| 0 | 0 | No rewardable material. |
| 1 | 1–3 | Basic understanding. Names legislation with limited application to the organisation's data. (AO2) |
| 2 | 4–6 | Good application. Discusses several legal requirements and how they apply to client data with some development. (AO2/AO3a) |
| 3 | 7–9 | Comprehensive evaluation. Thorough discussion of legal obligations (GDPR, Computer Misuse Act), client rights and consequences of breach, with a balanced judgement. (AO2/AO3a/AO3b) |
Question 3 Total: 21 marks
Question 4 — Cloud & Servers (24 marks total)
Award up to three marks for an accurate description of how the organisation can use a cloud computing model.
- Identifies a model (e.g. IaaS/SaaS/PaaS or cloud backup service) (1)
- Describes how data is stored on remote servers managed by a provider (1)
- Explains access over the internet rather than on-site hardware (1)
Accept any appropriate cloud model correctly described
Indicative Content (not prescriptive — reward any well-developed point)
- Infrastructure as a Service (IaaS) — rental of servers/storage; most control, most management
- Platform as a Service (PaaS) — development platform; middle level of control
- Software as a Service (SaaS) — ready-made application; least control, least management
- Private cloud — dedicated to one organisation; more secure, more costly
- Public cloud — shared provider; cheaper, less control
- Hybrid cloud — mixes private and public; balances security and cost
- For backup: public cloud/IaaS is cost-effective for large data volumes
- Security/compliance considerations for the specific organisation
- Scalability — cloud scales up/down with demand
- Cost — pay-as-you-go vs capital expenditure
| Level | Mark | Descriptor |
| 0 | 0 | No rewardable material. |
| 1 | 1–3 | Basic understanding of cloud models. Names one or two models (IaaS/PaaS/SaaS or public/private) with limited application. (AO2) |
| 2 | 4–6 | Good evaluation. Compares several cloud models and how they could meet the organisation's needs, with some development. (AO2/AO3a) |
| 3 | 7–9 | Comprehensive evaluation. Thorough comparison of multiple cloud models (service and deployment), evaluated against the organisation's needs, security, cost and scalability, with a justified recommendation. (AO2/AO3a/AO3b) |
Indicative Content (not prescriptive — reward any well-developed point)
- Web server — serves web pages over the internet; enables public access
- File server — stores and shares files on a local network; controlled centrally
- Performance: web server optimised for concurrent HTTP requests; file server for file I/O throughput
- Efficiency: web server caches content and handles many simultaneous clients; file server provides centralised storage
- Security: web server exposed to the internet (needs strong protection); file server on the internal network is more contained
- Accessibility: web server accessible remotely; file server typically LAN/remote access only
- Suitability depends on need — serving content publicly vs internal file sharing
- Cost and management considerations of each
| Level | Mark | Descriptor |
| 0 | 0 | No rewardable material. |
| 1 | 1–4 | Basic understanding of web server and/or file server. Limited comparison, mostly descriptive. (AO2) |
| 2 | 5–8 | Good evaluation comparing performance and efficiency of web server vs file server with several points developed in context. (AO2/AO3a) |
| 3 | 9–12 | Comprehensive evaluation. Thorough, balanced comparison covering performance, efficiency, security, accessibility and suitability, clearly contextualised, with a justified conclusion. (AO2/AO3a/AO3b) |
Question 4 Total: 24 marks Paper Total: 90 marks