As general purpose operating systems go, there was another interesting article from earlier this year comparing popular Linux distros which found that Ubuntu (18.04) had the best overall posture with regard to use of hardening and mitigation mechanisms out-of-the-box vs. versions of CentOS/RHEL, Debian, and OpenSUSE at the time. Some of this was due to the newer Linux kernel version being used, but also thanks to hardening of binaries, etc.
> Our experiments indicate that Ubuntu 18.04 shows the largest adoption of OS and application-level mitigations, followed by Debian 9.
https://capsule8.com/blog/millions-of-binaries-later-a-look-...
I’d go so far as to say that you shouldn’t touch a FreeBSD or OpenBSD install unless you’ve already done and maintained a gentoo, arch, or LFS install.
And by "post install configuration," I mean adding XFCE or other DE or WM, along with whatever apps you like. No tweaking needed to close security holes.
I’d say it’s about equivalent to a simple Arch install on easy hardware, although OpenBSD comes with quite a bit more security stuff pre-configured.
While you're doing the initial configuration, you get to learn a good deal about what the OS is made of. I found investing a little time to get familiarized with the system components results in more confidence as a user, rather than simply letting the OS do its magic and then wondering how it works later on. Like moving into a new house... You want to know where the fuses are and how to shut off the gas valve.