The importantdomain.com records. When you have example.com CNAME example.net, that is a record describing example.com and therefore it belongs in the example.com zone.
Another way to think about this in this context is that the CNAME record that you create will delegate the ability to create certificates for importantdomain.com to aliasdomainforvalidationonly.com. Only someone who already controls DNS for importantdomain.com should be able to create this delegation! (For example, you shouldn’t be able to get certificates for google.com or microsoft.com just by editing DNS records for some other domain.)