More or less what the steps NordVPN tech support explained to me.
In short, create a hotspot on a PC wired physically to the router, turn on VPN on that PC, get XSX to login into that VPN-ed hotspot created on that PC, voila!
Unfortunately that is not a long term solution for me. I cannot leave a PC running every time I got the itch to watch a show on Hulu or HBO Max.
TripleB's option is much more elegant and permanent, ie; I can leave the VPN running indefinitely if I can tunnel the XSX console to only accept a VPN-ed connection, without VPN-ing the entire home network.

I could just turn VPN on and off by the Asus app on my phone, but that introduces rubberbanding connection between a tunneled VPN connection and back to local connection un-VPN-ed. Or I could just do what I'm currently using now, stick with my current dedicated streaming device ( that is not the XSX, it's currently a Fire TV 4K Max) and just live with it.
The whole reason why I'm keen in pursuing a VPN-ed XSX is that my Microsoft account is already a US account. VPN-ing that account on my XSX just makes sense, and opens up all the features currently enjoyed by US-located user with their XSX. It's infuriating seeing I can download the HBO Max and Disney+ app on the console itself and not able to do anything about it just because I'm stuck in here. I'll be happy to subscribe if HBO Max and Hulu is available here locally. Disney+ is available here but not at the highest quality settings with 4K Dolby Vision and Dolby Atmos. Disney+ Malaysia version only max out at 1080p 5.1 audio, due to the service provider running the streaming service under a web browser protocol wrapped in an app-like interface.
VPN-ing the XSX also means I can simplify my setup/routine.
Currently it's: turn on Fire TV 4K Max , turn on NordVPN on Fire TV 4K Max, wait till it has secured a firm connection with NordVPN USA, then only can boot up HBO Max, Hulu, Disney+.
If I can VPN only the XSX: turn on SXS with the controller.....done. VPN is done automatically on router, and permanently too if I can tunnel that VPN specifically only for the XSX.
» Click to show Spoiler - click again to hide... «
First world problems, I know. If things like these are not a big deal to you, I understand too. I mean, I can easily torrent and get these shows for viewing, I just want to turn on the TV and watch my shows without having to track down torrent links and try to present that movie file to watch on the living room TV to watch. I'm too old to deal with that ghettoness (I'm still forced to go that route though, on shows not offered by the big streaming three services, but they're obscure shows for my own onsumption.) and I just want to watch my shows with a few button taps on the remore/controller after a hard day WFH.
The only thing you're missing out without VPN is xbox gamepass Cloud, MS rewards (you can earn those through a VPN on your phone though) and maybe VOD from the Microsoft store.
If all you want is geo-fenced media content, instead of insisting on using VPN, why not try using a smart DNS provider like I suggested earlier? Like you I'm too old and lazy to be bothered with torrenting or keeping my plex server up and running 24/7 and it's just easier to pay a subscription to have proper VOD. My Disney+ is 4k with Dolby Vision, but at the same time so is my MY netflix and MY apple TV because only the sites that you're trying to umblock use the smart-dns service. Also, if you're looking for a VPN solution, all your console traffic will get routed through the VPN. This will also negatively impact your online gaming experience.
For HBO max specifically, the xbox app supports 4k HDR and not 4k dolby vision last i tested.
Finally, since you're already using nordvpn, it already supports smart DNS...
Seriously this is the more elegant streaming solution. my process: turn on xbox+tv, select streaming app, watch.