Refer to the exhibit.
An administrator is configuring FortiNAC-F (or the onboarding of guest users. Which IP address would be used for the gateway defined in the DHCP scope?
Suggested Answer: D
Explanation:
The correct answer is D. The question is about guest onboarding, and the exhibit shows the Guest Network using gateway 10.20.1.250. In a Layer 3 captive network design, FortiNAC-F provides DHCP and DNS services to isolated or captive-network hosts, but the DHCP scope must still give the endpoint the correct default gateway for the network where that endpoint is placed. The study guide specifically warns that, when configuring Layer 3 captive network scopes, the administrator must think from the isolated host's perspective for the IP pool and gateway configuration. It also states that each captive network interface configuration includes an IP address, subnet mask, default gateway, and one or more DHCP scopes.
Option A, 10.0.1.254, is the infrastructure gateway on the FortiNAC-F service/production-side segment, not the guest network gateway. Option B, 10.0.1.110, is the FortiNAC-F interface address shown in the diagram, not the default gateway for guest clients. Option C, 10.10.1.250, is the gateway for the Isolation Network, not the Guest Network. Since the administrator is configuring guest onboarding, the DHCP scope for guest users must hand out 10.20.1.250 as the gateway.