The built in firewall protects you from incoming threats (although it doesn't have an easy to use UI). ZoneAlarm, NIS, etc also protect you from 'outgoing' threats (e.g. somehow a trojan got on your machine, they help limit the trojans ability to connect outward)
Bill