For a Layer7 rule, Both the DROP and REJECT actions generate response packets (RST for TCP).
This behavior is different as compared to the Layer4 Drop rules (where response packets are not generated).
For layer7 inspection, VMware leaks few initial packets of a connection until protocol detection. Therefore, the response packets are generated on both DROP and REJECT cases to cleanup the states created on the client and server.