That root certificate is more recent and therefore even less well trusted. Besides, it's also cross-signed by ISRG Root X1, so that little fact isn't of that importance.
No it doesn't. Your server at simon4d.bel.com is only sending the leaf certificate. It might be configured (I dunno) to "see" the full chain, but it isn't using it entirely.
Don't ask me how to change that, as I don't have experience with 4D, win-acme or Windows in general nowadays.