If you are talking about a fully integrated AD/DNS domain then yes, they should (with the default security setup and assuming there are no firewalls etc between) access each other's DNS databases. The integration sorts it all out for you. There are configs you can do to prevent replication or routing but that is a later change.