The honest answer
These two are often treated as the same thing. They are not. Robots.txt controls crawling, which is whether a crawler may visit an address. Noindex controls indexing, which is whether a page may appear in results.
If your goal is to keep a page out of search, noindex is the one that does it. Leave the page open to crawlers and add the tag. Google reads the page, finds the instruction and keeps the page out of results.
Robots.txt cannot promise that. A blocked page can still be indexed without its content if other pages link to it. It can show up as a bare address with no description.
The worst choice is both on the same page. If robots.txt blocks the address, the crawler never reads the noindex tag, so the tag does nothing.
Robots.txt still has a job. Use it for areas where crawling is a waste of time, such as cart pages and internal search results. Neither one is a lock. Anyone with the address can open the page, so private content needs a login.
The full explanation is in crawling and indexing, explained simply. To check one of your own pages, run the free audit.