Typically zero authentication is the best solution. Personally I (and I think most of us) press lock button automatically. To unlock Face ID / Touch ID / PIN is required. So, I don't see reason in additional annoying check.
Of course, there are bank's applications and similar, where security is too important. If to select beetween methods, I prefer password (PIN).
IMO, 'secret' apps should automatically log off, if user does not work with app, for example, 1-2 minutes.