There is no single best setup because people have different needs. Ideally you would use full disk encryption with or without a hidden volume (I'm not sold on the effectiveness of hidden volumes at stifling LE investigation, but it probably wouldn't hurt to use one either). However, some people can't use FDE for whatever reason. They may share a computer with others or only get internet access at a library or cafe, so they use a bootable distro like Tails, or they keep their sensitive files on an encrypted thumb drive. Likewise, Linux is safer than Windows, and OpenBSD is safer still, but most people are wedded to Windows/OS X for one reason or another. Security in practice is weighed against the trade offs of convenience and practicality, and the optimal trade off point will be different for everyone.