This question can be tested in two parts: first fixing what counts as the civil baseline under the IT Act, then identifying what extra element pushes conduct into criminal territory.
Test 1, civil baseline:
Section 43 makes unauthorised access to or damage of a computer resource a civil wrong calling for compensation, without requiring any particular state of mind beyond the act itself, and without regard to monetary damage or who initiated proceedings.
Test 2, criminal add-on:
Chapter XI's offences, covering hacking, identity theft, and cheating by personation, all require the same underlying unauthorised conduct to be accompanied by dishonest or fraudulent intent.
Conclusion:
Only the presence of dishonest or fraudulent intent supplies the missing ingredient that Test 2 requires, while a monetary threshold, the victim's choice to sue criminally, or plain unauthorised access without intent all remain within the civil baseline of Test 1.
Criminal law generally reserves punishment for conduct backed by a guilty state of mind, while civil remedies simply address harm regardless of intent. The IT Act's split between civil contraventions and criminal offences follows this same purpose, and testing each option against it shows which one actually fits.
Only dishonest or fraudulent intent captures the guilty state of mind that criminal law exists to punish.
Therefore, the correct answer is When the act is done dishonestly or fraudulently in addition to unauthorised access.