I agree with @JaredBusch reasoning for not pointing at DC's only in DNS, though his newly proposed solution is pretty cool - assuming the ERL will flip back to the primary as soon as it's available.
As for the secondary DNS server, assuming you have a standard Windows license, it's really kinda six of one, half dozen of another if you should setup a second VM as an additional DC. I see both sides, can't say that one way or the other is really better. I suppose it's a matter of resources.