Currently, WordPress sets up a site with no active protection against comment spam, but with comments enabled on the samples.
That this is not best practice can be seen by the fact that a search for '"Welcome to WordPress. This is your first post. Edit or delete it, then start blogging!" viagra' produces over one and a half million hits.
Use some other typical spam words, and it's worse.
Comments are lovely, but they should only be turned on when the site is ready, i.e. is using Akismet or an equivalent service.