maybe controversial take, but zone transfers are not vulnerability, there's nothing really private in that
There's NO REASON to have zone transfer enabled.
There are absolutely reasons to have zone transfer enabled -- to transfer the zones from primary/authoritative DNS servers to secondary DNS servers.
Zone transfers should, however, be limited to just the secondary DNS servers and not open to the world.