a short question regarding dns zone

I have a short question and I need an answer that explain the best option to make in this scenario:

An administrator is faced with a BYOD Environment and configures a Windows DNS server and create a standalone (non-AD integrated) forward lookup zone that corresponds with their DHCP scope. A junior security engineer says you need to set the zone to only allow secure updates, but needs the administrator’s approval to make the change.

Is this a good Idea, what are the benefits and/or disadvantages to changing that setting in this environment?


