A zone is a collection of controllers under a single administrative domain. This could be a single controller, or a cluster of controllers. The MC controllers in a zone terminate all the tunnels for the APs that they control.
For example, you have a standalone controller in the DMZ. This controller puts the Guest WLAN on the corporate APs. This means that all corporate APs support connectivity for guests. So, the APs are all controlled by corporate MCs in the Primary zone, and corporate employee WLANs are tunneled to these same controllers. However, all Guest WLAN traffic is tunneled to the controller in the DMZ.
This gives you a more distinct separation between corporate and guest traffic.