Hello,
You are right is saying that:
If no intrazone policy is configured, traffic will match default policy.
MGT is a special functional zone. Only dedicated management interfaces can be assigned to MGT. Traffic coming on MGT zone has to be packet destined for the device itself e.g. SSH, Telnet to the box.
Traffic can not come on MGT interface & leave from other interface in other zone.
http://www.juniper.net/documentation/en_US/junos11.4/topics/concept/zone-functional-understanding.html
Regards,
Rushi