Most first-day incidents are solved with a handful of tools used carefully. The skill is less in knowing exotic flags than in avoiding a few classic mistakes.
Look before you touch. ls -la, stat, file, and head answer "what is this?" without changing anything. realpath and readlink -f resolve symlinks, so you know which file a path really names. On a shared host, find out whether a file is the active one before editing it.
Understand expansion. The shell rewrites your command before the program sees it. It expands * to filenames, $VAR to values, and ~ to your home directory, and it splits on spaces. A path like release notes/v2.txt becomes two arguments unless it is quoted. Quote variables by default ("$path"), and use -- before arguments that may start with a dash. echo the command first when a glob could match more than you expect.
Redirect deliberately. > truncates and >> appends. 2>&1 merges errors into output, and order matters: cmd > out.txt 2>&1 captures both, while cmd 2>&1 > out.txt does not. tee shows output and keeps a copy, which is the right default during an incident.
Search with intent. grep -rn PATTERN DIR finds where something is mentioned. find DIR -name ... -mtime ... -size ... finds files by metadata. sort | uniq -c | sort -n turns a log into a frequency table. When counting, count the thing the question asks about, for example failed jobs, not lines containing "fail".
Remove narrowly. Prefer an explicit path to a glob, and rm -i or ls with the same pattern first. Nothing on a Unix system has a recycle bin.
Environment is per process. A variable set in your shell without export is invisible to child processes. One set in your shell is invisible to services and cron jobs.