This question can be answered by tracking how the Act itself is structured: one provision creates civil liability for a list of computer-related acts, and a separate provision escalates the same acts into a crime once a mental element is added.
Because the Act's own two-layer structure specifically uses dishonest or fraudulent intent as the trigger for criminal liability, the correct answer is that the conduct becomes criminal when it is done dishonestly or fraudulently in addition to unauthorised access.
This question can also be answered using a basic principle that runs through criminal law generally: a wrong becomes a crime, rather than remaining a purely compensable civil wrong, when it is accompanied by a blameworthy state of mind, and testing the four options against that general principle gives the same result.
Applying the general principle that a guilty mind is what converts a wrong into a crime, the only option that actually supplies that guilty mind is the one requiring dishonest or fraudulent conduct alongside unauthorised access, which is therefore the correct answer.