Yes, if you don't need to enable any protocol or service (I'm not sure if the dhcp service is configured in the factory default configuration) on the interfaces of that zone, but only the management, it seems a good option; you may also configure a firewall filter to apply more restrictive policies to telnet and http traffic (here it is the related KB).