We're running Windows 2008 AD Integrated DNS and a few Secondary Zones. After reviewing current DNS setup Aging is not set and Zone transfers are configured to "Only to servers listed on the Name Servers tab". From what I've read Zone Transfers is designed for Secondary Zones and AD Integrated DNS is not required because it's stored in the AD database which is handled by AD replication.
1) Is it wrong to have all AD Integrated DNS and Secondary configured for Zone transfers?
2) Should I list the secondary zones only in the Zone Transfers?
As for Zone Aging/Scavenging I found this unchecked. Isn't it recommended to have this enabled to clear out stale records?