WGU E026 TASK 3
AI Network Automation
Evaluation and Business Proposal
Performance evaluation | Traditional comparison | Cost-benefit analysis
Resource utilization | Scalability | Governance
Student: [Replace with your name]
Student ID: [Replace with your ID]
Date: [Replace with submission date]
Professional business proposal
2026 Edition
, Submission Readiness Notice
Important: The financial values and performance figures in this proposal are planning assumptions and target service
levels. They must be replaced or reconciled with measured Task 2 evidence, actual vendor quotes, organizational
labor rates, and the current WGU rubric before submission. Only an evaluator can determine whether a submission
passes.
This business proposal evaluates the AI-enabled network modernization program developed across E026 Tasks 1 and 2. The
document is written in third-person voice and treats Palo Alto Networks PA-Series or VM-Series with Advanced Threat Prevention
as the named production firewall and IDS/IPS vendor solution.
Rubric area Proposal evidence
A Project scope, objectives and implementation review
B/H Performance targets, traditional comparison and verification framework
C/I Acquisition costs, operational benefits, ROI and payback
D/J CPU, memory, storage, bandwidth and scalability analysis
E APA-style professional references
A. Executive Project Summary
A1. Project Scope and Objectives
The modernization program addresses a mid-sized enterprise that must integrate an on-premises network with a cloud network
while improving operational consistency, security visibility, and response speed. The target architecture retains nonoverlapping
private address spaces, segmented user, server, management, and security zones, encrypted hybrid connectivity, centralized
telemetry, and least-privilege control. Palo Alto Networks provides the named firewall and IDS/IPS enforcement boundary. The
analytics layer adds predictive maintenance, behavioral anomaly detection, and supervised alert classification.
The program has five strategic objectives:
1. Reduce configuration lead time and error rates through validated, repeatable automation. 2. Reduce mean time to detect and
contain high-confidence security events. 3. Improve infrastructure availability through predictive device-health analysis. 4. Support
cloud growth without proportional growth in manual administrative effort. 5. Govern AI output through testing, approval gates,
version control, auditability, and rollback.
The hybrid design bridges the enterprise and cloud through a routed security boundary. On-premises VLANs feed a core router and
Palo Alto Networks firewall. The firewall applies zone policy, approved security profiles, and logging before traffic reaches the cloud
gateway and private application subnet. Telemetry from firewalls, authentication services, routers, switches, endpoints, DNS, and
cloud audit services is normalized and evaluated by deterministic rules and AI models. High-confidence detections enter a SOAR
workflow; disruptive containment remains subject to explicit policy and approval.
A2. Implementation Review
Task 2 translated the design into a streamlined GNS3 proof of concept. A core router supplied inter-VLAN routing, an access switch
supplied 802.1Q segmentation, a Palo Alto Networks VM-Series node represented the named threat-prevention boundary, and a
cloud router/workload represented the private cloud zone. The design intentionally reduced redundant appliances to meet lab CPU
and memory constraints while preserving trust boundaries and traffic flows.
The implementation included:
• A Netmiko automation program that read a JSON inventory, acquired credentials at runtime, deployed role-based configuration,
saved device state, and recorded before/change/after evidence.
• A telemetry parser that accepted syslog or JSON, validated timestamps and IP addresses, normalized severity, counted repeated
authentication failures, mapped qualifying events to MITRE ATT&CK T1110, and emitted JSONL alerts.
• A structured API payload that carried event identity, source, destination, severity, evidence, requested action, and time-to-live.
WGU E026 Task 3 | AI Network Automation Evaluation Page 2 of 11
AI Network Automation
Evaluation and Business Proposal
Performance evaluation | Traditional comparison | Cost-benefit analysis
Resource utilization | Scalability | Governance
Student: [Replace with your name]
Student ID: [Replace with your ID]
Date: [Replace with submission date]
Professional business proposal
2026 Edition
, Submission Readiness Notice
Important: The financial values and performance figures in this proposal are planning assumptions and target service
levels. They must be replaced or reconciled with measured Task 2 evidence, actual vendor quotes, organizational
labor rates, and the current WGU rubric before submission. Only an evaluator can determine whether a submission
passes.
This business proposal evaluates the AI-enabled network modernization program developed across E026 Tasks 1 and 2. The
document is written in third-person voice and treats Palo Alto Networks PA-Series or VM-Series with Advanced Threat Prevention
as the named production firewall and IDS/IPS vendor solution.
Rubric area Proposal evidence
A Project scope, objectives and implementation review
B/H Performance targets, traditional comparison and verification framework
C/I Acquisition costs, operational benefits, ROI and payback
D/J CPU, memory, storage, bandwidth and scalability analysis
E APA-style professional references
A. Executive Project Summary
A1. Project Scope and Objectives
The modernization program addresses a mid-sized enterprise that must integrate an on-premises network with a cloud network
while improving operational consistency, security visibility, and response speed. The target architecture retains nonoverlapping
private address spaces, segmented user, server, management, and security zones, encrypted hybrid connectivity, centralized
telemetry, and least-privilege control. Palo Alto Networks provides the named firewall and IDS/IPS enforcement boundary. The
analytics layer adds predictive maintenance, behavioral anomaly detection, and supervised alert classification.
The program has five strategic objectives:
1. Reduce configuration lead time and error rates through validated, repeatable automation. 2. Reduce mean time to detect and
contain high-confidence security events. 3. Improve infrastructure availability through predictive device-health analysis. 4. Support
cloud growth without proportional growth in manual administrative effort. 5. Govern AI output through testing, approval gates,
version control, auditability, and rollback.
The hybrid design bridges the enterprise and cloud through a routed security boundary. On-premises VLANs feed a core router and
Palo Alto Networks firewall. The firewall applies zone policy, approved security profiles, and logging before traffic reaches the cloud
gateway and private application subnet. Telemetry from firewalls, authentication services, routers, switches, endpoints, DNS, and
cloud audit services is normalized and evaluated by deterministic rules and AI models. High-confidence detections enter a SOAR
workflow; disruptive containment remains subject to explicit policy and approval.
A2. Implementation Review
Task 2 translated the design into a streamlined GNS3 proof of concept. A core router supplied inter-VLAN routing, an access switch
supplied 802.1Q segmentation, a Palo Alto Networks VM-Series node represented the named threat-prevention boundary, and a
cloud router/workload represented the private cloud zone. The design intentionally reduced redundant appliances to meet lab CPU
and memory constraints while preserving trust boundaries and traffic flows.
The implementation included:
• A Netmiko automation program that read a JSON inventory, acquired credentials at runtime, deployed role-based configuration,
saved device state, and recorded before/change/after evidence.
• A telemetry parser that accepted syslog or JSON, validated timestamps and IP addresses, normalized severity, counted repeated
authentication failures, mapped qualifying events to MITRE ATT&CK T1110, and emitted JSONL alerts.
• A structured API payload that carried event identity, source, destination, severity, evidence, requested action, and time-to-live.
WGU E026 Task 3 | AI Network Automation Evaluation Page 2 of 11