Emily But before first unlock, I notice that WiFi icon appears on the screen while the VPN icon does not appear.
Does it mean that the WiFi is on the working status while VPN is not?
Yes.
Emily Does it mean the internet traffic could bypass always-on VPN setting before first unlock?
It shouldn't, and the presence of the Wi-Fi icon does not mean it is.
When the device is rebooted and BFU, it is expected that the device, if it has a SIM and isn't in airplane mode, will connect to the cellular network to receive incoming calls and support outgoing emergency calls. If the cellular network icon is on that will not mean that anything is using the cellular connection, just that the connection is available.
When the device is rebooted and BFU, it is expected that the device, if it is near a Wi-Fi network it can sign in to, will connect to the Wi-Fi network. This can be useful if the device has Wi-Fi calling enabled, since the device could use the Wi-Fi network to receive incoming calls and support outgoing emergency calls. Also, system functions such as connectivity and network time (source) can use the Wi-Fi network.
If the Wi-Fi network icon is on that will not mean that apps that should be blocked by the VPN are using the Wi-Fi connection, just that the connection is available.